Hi all,
I'm evaluating Splunk and have a few questions.
1. Our main server is running on CentOs and most our our application clients will be on windows. Since all these nodes mirror one another, can I install the splunk forwarder on a single node then copy the configurations to each machine? I'm using splunk forwarders with no web interface.
2. Our applications have custom performance counters in them. I've found this post which outlines how to dump data from performance counters to file.
http://www.splunk.com/base/Documentation/3.4.10/Admin/WindowsProcessMonitoring
I've decided to use tab delimited in my output format. Is there any way to assign a human readable label to each column? For instance, mine will have 3 numeric values which represent failed tries, average delta between operations, and average operations per second.
Thanks,
Todd
[Revised on Sun, 05 Jul 2009 18:55:21 -0700]
Forgot to ask. Is it possible to define the file observations from the web interface?