Professional Documents
Culture Documents
Windows
Splunk Splunk Windows Windows
Data Inputs WMI DBA Data Input Splunk
IT Splunk Windows
WMI
WMI(Windows Management Instrumentation) Windows
Windows
WMI of CPU
CPU
(WMI of CPU)
()
(WMI of CPU)
WMI
Scriptomatic
WQL
wql = select AvailableMBytes from Win32_PerfFormattedData_PerfOS_Memory
Scriptomatic Windows SQL
ExchangeWindows
Splunk 3.x.x Splunk (wmi.conf) WQL WMI
Splunk 4.x.x
WMI Splunk 4.x.x WMI
STEP 2:
ManagerData Inputs
STEP 3:
Data InputsWMI collectionsAdd New
Splunk for WMI
STEP 4:
Collection name WMI Select target hostQuery
STEP 5:
QueryAvailable classes WMI Class
Note
Available
Available classes
classes
WMI Class
Class
SQL
SQL
Available classes
classes
SQL
STEP 6:
STEP 7:
(Enable)Save
WMI
STEP 8:
WMI data collections WMI Query
STEP 9:
WMI data collectionsSearch
Source Sourcetype WMI:Local
Physical Information Index 5
CPU (
()
)
(
()
)
WMI IBM PerceivedSeverity=6
PerceivedSeverity=4 PerceivedSeverity=2
CPU
CPU High(>95%),Warn(80%~94%),OK(<80%)
* VPU
Splunk
4.0.3
500MB IT Data
http://www.splunk.com
http://www.splunk.com/download/?ac=Partner_Systex%20
: http://www.systex.com.tw
Splunk www.splunklab.net