You are on page 1of 9

Splunk

Windows
Splunk Splunk Windows Windows
Data Inputs WMI DBA Data Input Splunk
IT Splunk Windows

WMI Splunk Windows Splunk 3.x.x WMI


Windows Splunk 4.x.x
Splunk for WMI

WMI
WMI(Windows Management Instrumentation) Windows
Windows

System Center Operation Management(SCOM) WMI


IBMHP WMIWMI VBScript

Splunk for WMI


Splunk WMI VBScript Splunk WQL
WMI WMI CPU
Select


WMI of CPU

CPU

wql = select PercentProcessorTime from Win32_PerfFormattedData_PerfOS_Processor


(CPU )

(WMI of CPU)

wql = select PercentProcessorTime,


PercentProcessorTime, PercentUserTime from Win32_PerfFormattedData_PerfOS_Processor
(CPU )

()

(WMI of CPU)

WMI
Scriptomatic

WQL
wql = select AvailableMBytes from Win32_PerfFormattedData_PerfOS_Memory
Scriptomatic Windows SQL
ExchangeWindows
Splunk 3.x.x Splunk (wmi.conf) WQL WMI
Splunk 4.x.x
WMI Splunk 4.x.x WMI

Splunk for WMI


STEP 1:
1:
Splunk http://www.splunk.com/download
Splunk
64-Bit Splunk 4.0.3 WMI Windows
Windows Splunk 5 Splunk
http://localhost:8000 adminchangeme

STEP 2:
ManagerData Inputs

STEP 3:
Data InputsWMI collectionsAdd New
Splunk for WMI

STEP 4:
Collection name WMI Select target hostQuery

STEP 5:
QueryAvailable classes WMI Class
Note
Available
Available classes
classes
WMI Class
Class
SQL
SQL
Available classes
classes
SQL

STEP 6:

STEP 7:
(Enable)Save
WMI

STEP 8:
WMI data collections WMI Query

STEP 9:
WMI data collectionsSearch
Source Sourcetype WMI:Local
Physical Information Index 5

Splunk wmi.conf Splunk 3.x.x

[WMI:Local Physical Information]


disabled = 0
interval = 300
server = localhost
wql = SELECT AvgDiskWriteQueueLength, CurrentDiskQueueLength FROM Win32_PerfFormattedData_PerfDisk_PhysicalDisk
WHERE Name="_Total"

Splunk for WMI


WMI Splunk Index Splunk

CPU (
()
)

sourcetype=="WMI:Local Processor Information" | timechart avg(PercentProcessorTime)


avg(PercentProcessorTime) as "CPU %Processor"
by host

* CPU ( Splunk 3.x.x )

(
()
)
WMI IBM PerceivedSeverity=6
PerceivedSeverity=4 PerceivedSeverity=2

sourcetype="WMI:IBM Hardware Event Information" PerceivedSeverity=6 | timechart avg(PerceivedSeverity)


as "IBM Hardware
Hardware Failure"

CPU
CPU High(>95%),Warn(80%~94%),OK(<80%)

sourcetype="WMI:Local Processor Information" | eval range=case(PercentProcessorTime<80, "OK (<80%)",


PercentProcessorTime<95, "Warn (80%(80%-94%)", 1==1, "High (95%+)") | chart count as "CPU %ProcTime
Count" by range

* VPU

WMI Windows Windows Splunk


Splunk for WMI IT

Splunk for WMI Splunk Splunk


for VMWareSplunk for Mac Address

Splunk
4.0.3
500MB IT Data
http://www.splunk.com
http://www.splunk.com/download/?ac=Partner_Systex%20
: http://www.systex.com.tw
Splunk www.splunklab.net

You might also like