Advertisement
Guest User

inputs.conf

a guest
Oct 17th, 2019
560
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 28.38 KB | None | 0 0
  1. # Copyright (C) 2019 Splunk Inc. All Rights Reserved.
  2. # DO NOT EDIT THIS FILE!
  3. # Please make all changes to files in $SPLUNK_HOME/etc/apps/Splunk_TA_windows/local.
  4. # To make changes, copy the section/stanza you want to change from $SPLUNK_HOME/etc/apps/Splunk_TA_windows/default
  5. # into ../local and edit there.
  6. #
  7.  
  8.  
  9.  
  10. ###### OS Logs ######
  11. [WinEventLog://Application]
  12. disabled = 1
  13. index = local
  14. start_from = oldest
  15. current_only = 0
  16. checkpointInterval = 5
  17. renderXml=true
  18.  
  19. [WinEventLog://Security]
  20. disabled = 1
  21. index = local
  22. start_from = oldest
  23. current_only = 0
  24. evt_resolve_ad_obj = 1
  25. checkpointInterval = 5
  26. blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"
  27. blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"
  28. renderXml=true
  29.  
  30. [WinEventLog://System]
  31. disabled = 1
  32. index = local
  33. start_from = oldest
  34. current_only = 0
  35. checkpointInterval = 5
  36. renderXml=true
  37.  
  38.  
  39. ###### Forwarded WinEventLogs (WEF) ######
  40. [WinEventLog://ForwardedEvents]
  41. disabled = 0
  42. index = local
  43. start_from = oldest
  44. current_only = 0
  45. checkpointInterval = 5
  46. ## The addon supports only XML format for the collection of WinEventLogs using WEF, hence do not change the below renderXml parameter to false.
  47. renderXml=true
  48. host=WinEventLogForwardHost
  49.  
  50.  
  51. ###### WinEventLog Inputs for Active Directory ######
  52.  
  53. ## Application and Services Logs - DFS Replication
  54. [WinEventLog://DFS Replication]
  55. disabled = 1
  56. renderXml=true
  57.  
  58. ## Application and Services Logs - Directory Service
  59. [WinEventLog://Directory Service]
  60. disabled = 1
  61. renderXml=true
  62.  
  63. ## Application and Services Logs - File Replication Service
  64. [WinEventLog://File Replication Service]
  65. disabled = 1
  66. renderXml=true
  67.  
  68. ## Application and Services Logs - Key Management Service
  69. [WinEventLog://Key Management Service]
  70. disabled = 1
  71. renderXml=true
  72.  
  73.  
  74. ###### WinEventLog Inputs for DNS ######
  75. [WinEventLog://DNS Server]
  76. disabled=1
  77. renderXml=true
  78.  
  79.  
  80. ###### DHCP ######
  81. [monitor://$WINDIR\System32\DHCP]
  82. disabled = 1
  83. whitelist = DhcpSrvLog*
  84. crcSalt = <SOURCE>
  85. sourcetype = DhcpSrvLog
  86.  
  87.  
  88. ###### Windows Update Log ######
  89. ## Enable below stanza to get WindowsUpdate.log for Windows 8, Windows 8.1, Server 2008R2, Server 2012 and Server 2012R2
  90. [monitor://$WINDIR\WindowsUpdate.log]
  91. disabled = 1
  92. sourcetype = WindowsUpdateLog
  93.  
  94. ## Enable below powershell and monitor stanzas to get WindowsUpdate.log for Windows 10 and Server 2016
  95. ## Below stanza will automatically generate WindowsUpdate.log daily
  96. [powershell://generate_windows_update_logs]
  97. script = ."$SplunkHome\etc\apps\Splunk_TA_windows\bin\powershell\generate_windows_update_logs.ps1"
  98. schedule = 0 */24 * * *
  99. disabled = 1
  100.  
  101. ## Below stanza will monitor the generated WindowsUpdate.log in Windows 10 and Server 2016
  102. [monitor://$SPLUNK_HOME\var\log\Splunk_TA_windows\WindowsUpdate.log]
  103. disabled = 1
  104. sourcetype = WindowsUpdateLog
  105.  
  106.  
  107. ###### Monitor Inputs for Active Directory ######
  108. [monitor://$WINDIR\debug\netlogon.log]
  109. sourcetype=MSAD:NT6:Netlogon
  110. disabled=1
  111.  
  112.  
  113. ###### Monitor Inputs for DNS ######
  114. [MonitorNoHandle://$WINDIR\System32\Dns\dns.log]
  115. sourcetype=MSAD:NT6:DNS
  116. disabled=1
  117.  
  118.  
  119. ###### Scripted Input (See also wmi.conf)
  120. [script://.\bin\win_listening_ports.bat]
  121. disabled = 1
  122. ## Run once per hour
  123. interval = 3600
  124. sourcetype = Script:ListeningPorts
  125.  
  126. [script://.\bin\win_installed_apps.bat]
  127. disabled = 1
  128. ## Run once per day
  129. interval = 86400
  130. sourcetype = Script:InstalledApps
  131.  
  132. [script://.\bin\win_timesync_status.bat]
  133. disabled = 1
  134. ## Run once per hour
  135. interval = 3600
  136. sourcetype = Script:TimesyncStatus
  137.  
  138. [script://.\bin\win_timesync_configuration.bat]
  139. disabled = 1
  140. ## Run once per hour
  141. interval = 3600
  142. sourcetype = Script:TimesyncConfiguration
  143.  
  144. [script://.\bin\netsh_address.bat]
  145. disabled = 1
  146. ## Run once per day
  147. interval = 86400
  148. sourcetype = Script:NetworkConfiguration
  149.  
  150. ###### Scripted/Powershell Mod inputs Active Directory ######
  151.  
  152. ## Replication Information NT6
  153. [script://.\bin\runpowershell.cmd nt6-repl-stat.ps1]
  154. source=Powershell
  155. sourcetype=MSAD:NT6:Replication
  156. interval=300
  157. disabled=1
  158.  
  159. ## Replication Information 2012r2 and 2016
  160. [powershell://Replication-Stats]
  161. script = & "$SplunkHome\etc\apps\Splunk_TA_windows\bin\Invoke-MonitoredScript.ps1" -Command ".\powershell\2012r2-repl-stats.ps1"
  162. schedule = 0 */5 * ? * *
  163. source = Powershell
  164. sourcetype=MSAD:NT6:Replication
  165. disabled=1
  166.  
  167. ## Health and Topology Information NT6
  168. [script://.\bin\runpowershell.cmd nt6-health.ps1]
  169. source=Powershell
  170. sourcetype=MSAD:NT6:Health
  171. interval=300
  172. disabled=1
  173.  
  174. ## Health and Topology Information 2012r2 and 2016
  175. [powershell://AD-Health]
  176. script = & "$SplunkHome\etc\apps\Splunk_TA_windows\bin\Invoke-MonitoredScript.ps1" -Command ".\powershell\2012r2-health.ps1"
  177. schedule = 0 */5 * ? * *
  178. source=Powershell
  179. sourcetype=MSAD:NT6:Health
  180. disabled=1
  181.  
  182.  
  183. ## Site, Site Link and Subnet Information NT6
  184. [script://.\bin\runpowershell.cmd nt6-siteinfo.ps1]
  185. source=Powershell
  186. sourcetype=MSAD:NT6:SiteInfo
  187. interval=3600
  188. disabled=1
  189.  
  190. ## Site, Site Link and Subnet Information 2012r2 and 2016
  191. [powershell://Siteinfo]
  192. script = & "$SplunkHome\etc\apps\Splunk_TA_windows\bin\Invoke-MonitoredScript.ps1" -Command ".\powershell\2012r2-siteinfo.ps1"
  193. schedule = 0 15 * ? * *
  194. source = Powershell
  195. sourcetype=MSAD:NT6:SiteInfo
  196. disabled=1
  197.  
  198.  
  199. ##### Scripted Inputs for DNS #####
  200.  
  201. ## DNS Zone Information Collection
  202. [script://.\bin\runpowershell.cmd dns-zoneinfo.ps1]
  203. source=Powershell
  204. sourcetype=MSAD:NT6:DNS-Zone-Information
  205. interval=3600
  206. disabled=1
  207.  
  208. ## DNS Health Information Collection
  209. [script://.\bin\runpowershell.cmd dns-health.ps1]
  210. source=Powershell
  211. sourcetype=MSAD:NT6:DNS-Health
  212. interval=3600
  213. disabled=1
  214.  
  215.  
  216. ###### Host monitoring ######
  217. [WinHostMon://Computer]
  218. interval = 600
  219. disabled = 0
  220. index = local
  221. mode = single
  222. type = Computer
  223.  
  224. [WinHostMon://Process]
  225. interval = 600
  226. disabled = 0
  227. index = local
  228. mode = single
  229. type = Process
  230.  
  231. [WinHostMon://Processor]
  232. interval = 600
  233. disabled = 0
  234. index = local
  235. mode = single
  236. type = Processor
  237.  
  238. [WinHostMon://NetworkAdapter]
  239. interval = 600
  240. disabled = 0
  241. index = local
  242. mode = single
  243. type = NetworkAdapter
  244.  
  245. [WinHostMon://Service]
  246. interval = 600
  247. disabled = 0
  248. index = local
  249. mode = single
  250. type = Service
  251.  
  252. [WinHostMon://OperatingSystem]
  253. interval = 600
  254. disabled = 0
  255. index = local
  256. mode = single
  257. type = OperatingSystem
  258.  
  259. [WinHostMon://Disk]
  260. interval = 600
  261. disabled = 0
  262. index = local
  263. mode = single
  264. type = Disk
  265.  
  266. [WinHostMon://Driver]
  267. interval = 600
  268. disabled = 0
  269. index = local
  270. mode = single
  271. type = Driver
  272.  
  273. [WinHostMon://Roles]
  274. interval = 600
  275. disabled = 1
  276. index = local
  277. type = Roles
  278.  
  279. ###### Print monitoring ######
  280. [WinPrintMon://printer]
  281. type = printer
  282. interval = 600
  283. baseline = 1
  284. disabled = 1
  285.  
  286. [WinPrintMon://driver]
  287. type = driver
  288. interval = 600
  289. baseline = 1
  290. disabled = 1
  291.  
  292. [WinPrintMon://port]
  293. type = port
  294. interval = 600
  295. baseline = 1
  296. disabled = 1
  297.  
  298. ###### Network monitoring ######
  299. [WinNetMon://inbound]
  300. direction = inbound
  301. disabled = 0
  302. index = local
  303. mode = single
  304.  
  305. [WinNetMon://outbound]
  306. direction = outbound
  307. disabled = 0
  308. index = local
  309. mode = single
  310.  
  311. ###### Splunk 5.0+ Performance Counters ######
  312. [perfmon://CPU]
  313. counters = % Processor Time; % User Time; % Privileged Time; Interrupts/sec; % DPC Time; % Interrupt Time; DPCs Queued/sec; DPC Rate; % Idle Time; % C1 Time; % C2 Time; % C3 Time; C1 Transitions/sec; C2 Transitions/sec; C3 Transitions/sec
  314. disabled = 0
  315. instances = *
  316. interval = 10
  317. mode = single
  318. object = Processor
  319. useEnglishOnly=true
  320.  
  321. ## Logical Disk
  322. [perfmon://LogicalDisk]
  323. counters = % Free Space; Free Megabytes; Current Disk Queue Length; % Disk Time; Avg. Disk Queue Length; % Disk Read Time; Avg. Disk Read Queue Length; % Disk Write Time; Avg. Disk Write Queue Length; Avg. Disk sec/Transfer; Avg. Disk sec/Read; Avg. Disk sec/Write; Disk Transfers/sec; Disk Reads/sec; Disk Writes/sec; Disk Bytes/sec; Disk Read Bytes/sec; Disk Write Bytes/sec; Avg. Disk Bytes/Transfer; Avg. Disk Bytes/Read; Avg. Disk Bytes/Write; % Idle Time; Split IO/Sec
  324. disabled = 0
  325. instances = *
  326. interval = 10
  327. mode = single
  328. object = LogicalDisk
  329. useEnglishOnly=true
  330.  
  331. ## Physical Disk
  332. [perfmon://PhysicalDisk]
  333. counters = Current Disk Queue Length; % Disk Time; Avg. Disk Queue Length; % Disk Read Time; Avg. Disk Read Queue Length; % Disk Write Time; Avg. Disk Write Queue Length; Avg. Disk sec/Transfer; Avg. Disk sec/Read; Avg. Disk sec/Write; Disk Transfers/sec; Disk Reads/sec; Disk Writes/sec; Disk Bytes/sec; Disk Read Bytes/sec; Disk Write Bytes/sec; Avg. Disk Bytes/Transfer; Avg. Disk Bytes/Read; Avg. Disk Bytes/Write; % Idle Time; Split IO/Sec
  334. disabled = 0
  335. instances = *
  336. interval = 10
  337. mode = single
  338. object = PhysicalDisk
  339. useEnglishOnly=true
  340.  
  341. ## Memory
  342. [perfmon://Memory]
  343. counters = Page Faults/sec; Available Bytes; Committed Bytes; Commit Limit; Write Copies/sec; Transition Faults/sec; Cache Faults/sec; Demand Zero Faults/sec; Pages/sec; Pages Input/sec; Page Reads/sec; Pages Output/sec; Pool Paged Bytes; Pool Nonpaged Bytes; Page Writes/sec; Pool Paged Allocs; Pool Nonpaged Allocs; Free System Page Table Entries; Cache Bytes; Cache Bytes Peak; Pool Paged Resident Bytes; System Code Total Bytes; System Code Resident Bytes; System Driver Total Bytes; System Driver Resident Bytes; System Cache Resident Bytes; % Committed Bytes In Use; Available KBytes; Available MBytes; Transition Pages RePurposed/sec; Free & Zero Page List Bytes; Modified Page List Bytes; Standby Cache Reserve Bytes; Standby Cache Normal Priority Bytes; Standby Cache Core Bytes; Long-Term Average Standby Cache Lifetime (s)
  344. disabled = 0
  345. interval = 10
  346. mode = single
  347. object = Memory
  348. useEnglishOnly=true
  349.  
  350. ## Network
  351. [perfmon://Network]
  352. counters = Bytes Total/sec; Packets/sec; Packets Received/sec; Packets Sent/sec; Current Bandwidth; Bytes Received/sec; Packets Received Unicast/sec; Packets Received Non-Unicast/sec; Packets Received Discarded; Packets Received Errors; Packets Received Unknown; Bytes Sent/sec; Packets Sent Unicast/sec; Packets Sent Non-Unicast/sec; Packets Outbound Discarded; Packets Outbound Errors; Output Queue Length; Offloaded Connections; TCP Active RSC Connections; TCP RSC Coalesced Packets/sec; TCP RSC Exceptions/sec; TCP RSC Average Packet Size
  353. disabled = 0
  354. instances = *
  355. interval = 10
  356. mode = single
  357. object = Network Interface
  358. useEnglishOnly=true
  359.  
  360. ## Process
  361. [perfmon://Process]
  362. counters = % Processor Time; % User Time; % Privileged Time; Virtual Bytes Peak; Virtual Bytes; Page Faults/sec; Working Set Peak; Working Set; Page File Bytes Peak; Page File Bytes; Private Bytes; Thread Count; Priority Base; Elapsed Time; ID Process; Creating Process ID; Pool Paged Bytes; Pool Nonpaged Bytes; Handle Count; IO Read Operations/sec; IO Write Operations/sec; IO Data Operations/sec; IO Other Operations/sec; IO Read Bytes/sec; IO Write Bytes/sec; IO Data Bytes/sec; IO Other Bytes/sec; Working Set - Private
  363. disabled = 0
  364. instances = *
  365. interval = 10
  366. mode = single
  367. object = Process
  368. useEnglishOnly=true
  369.  
  370. ## ProcessInformation
  371. [perfmon://ProcessorInformation]
  372. counters = % Processor Time; Processor Frequency
  373. disabled = 0
  374. instances = *
  375. interval = 10
  376. mode = single
  377. object = Processor Information
  378. useEnglishOnly=true
  379.  
  380. ## System
  381. [perfmon://System]
  382. counters = File Read Operations/sec; File Write Operations/sec; File Control Operations/sec; File Read Bytes/sec; File Write Bytes/sec; File Control Bytes/sec; Context Switches/sec; System Calls/sec; File Data Operations/sec; System Up Time; Processor Queue Length; Processes; Threads; Alignment Fixups/sec; Exception Dispatches/sec; Floating Emulations/sec; % Registry Quota In Use
  383. disabled = 0
  384. instances = *
  385. interval = 10
  386. mode = single
  387. object = System
  388. useEnglishOnly=true
  389.  
  390. [perfmon://Processor]
  391. object = Processor
  392. counters = % Processor Time; % User Time; % Privileged Time; Interrupts/sec; % DPC Time; % Interrupt Time; DPCs Queued/sec; DPC Rate; % Idle Time; % C1 Time; % C2 Time; % C3 Time; C1 Transitions/sec; C2 Transitions/sec; C3 Transitions/sec
  393. instances = *
  394. interval = 10
  395. disabled = 0
  396. mode = single
  397. useEnglishOnly=true
  398. index = perfmon
  399.  
  400. [perfmon://Network_Interface]
  401. object = Network Interface
  402. counters = Bytes Total/sec; Packets/sec; Packets Received/sec; Packets Sent/sec; Current Bandwidth; Bytes Received/sec; Packets Received Unicast/sec; Packets Received Non-Unicast/sec; Packets Received Discarded; Packets Received Errors; Packets Received Unknown; Bytes Sent/sec; Packets Sent Unicast/sec; Packets Sent Non-Unicast/sec; Packets Outbound Discarded; Packets Outbound Errors; Output Queue Length; Offloaded Connections; TCP Active RSC Connections; TCP RSC Coalesced Packets/sec; TCP RSC Exceptions/sec; TCP RSC Average Packet Size
  403. instances = *
  404. interval = 10
  405. disabled = 0
  406. mode = single
  407. useEnglishOnly=true
  408. index = perfmon
  409.  
  410. [perfmon://DFS_Replicated_Folders]
  411. object = DFS Replicated Folders
  412. counters = Bandwidth Savings Using DFS Replication; RDC Bytes Received; RDC Compressed Size of Files Received; RDC Size of Files Received; RDC Number of Files Received; Compressed Size of Files Received; Size of Files Received; Total Files Received; Deleted Space In Use; Deleted Bytes Cleaned up; Deleted Files Cleaned up; Deleted Bytes Generated; Deleted Files Generated; Updates Dropped; File Installs Retried; File Installs Succeeded; Conflict Folder Cleanups Completed; Conflict Space In Use; Conflict Bytes Cleaned up; Conflict Files Cleaned up; Conflict Bytes Generated; Conflict Files Generated; Staging Space In Use; Staging Bytes Cleaned up; Staging Files Cleaned up; Staging Bytes Generated; Staging Files Generated
  413. instances = *
  414. interval = 30
  415. disabled = 0
  416. mode = single
  417. useEnglishOnly=true
  418. index = perfmon
  419.  
  420. [perfmon://NTDS]
  421. object = NTDS
  422. counters = DRA Inbound Properties Total/sec; AB Browses/sec; DRA Inbound Objects Applied/sec; DS Threads in Use; AB Client Sessions; DRA Pending Replication Synchronizations; DRA Inbound Object Updates Remaining in Packet; DS Security Descriptor sub-operations/sec; DS Security Descriptor Propagations Events; LDAP Client Sessions; LDAP Active Threads; LDAP Writes/sec; LDAP Searches/sec; DRA Outbound Objects/sec; DRA Outbound Properties/sec; DRA Inbound Values Total/sec; DRA Sync Requests Made; DRA Sync Requests Successful; DRA Sync Failures on Schema Mismatch; DRA Inbound Objects/sec; DRA Inbound Properties Applied/sec; DRA Inbound Properties Filtered/sec; DS Monitor List Size; DS Notify Queue Size; LDAP UDP operations/sec; DS Search sub-operations/sec; DS Name Cache hit rate; DRA Highest USN Issued (Low part); DRA Highest USN Issued (High part); DRA Highest USN Committed (Low part); DRA Highest USN Committed (High part); DS % Writes from SAM; DS % Writes from DRA; DS % Writes from LDAP; DS % Writes from LSA; DS % Writes from KCC; DS % Writes from NSPI; DS % Writes Other; DS Directory Writes/sec; DS % Searches from SAM; DS % Searches from DRA; DS % Searches from LDAP; DS % Searches from LSA; DS % Searches from KCC; DS % Searches from NSPI; DS % Searches Other; DS Directory Searches/sec; DS % Reads from SAM; DS % Reads from DRA; DRA Inbound Values (DNs only)/sec; DRA Inbound Objects Filtered/sec; DS % Reads from LSA; DS % Reads from KCC; DS % Reads from NSPI; DS % Reads Other; DS Directory Reads/sec; LDAP Successful Binds/sec; LDAP Bind Time; SAM Successful Computer Creations/sec: Includes all requests; SAM Machine Creation Attempts/sec; SAM Successful User Creations/sec; SAM User Creation Attempts/sec; SAM Password Changes/sec; SAM Membership Changes/sec; SAM Display Information Queries/sec; SAM Enumerations/sec; SAM Transitive Membership Evaluations/sec; SAM Non-Transitive Membership Evaluations/sec; SAM Domain Local Group Membership Evaluations/sec; SAM Universal Group Membership Evaluations/sec; SAM Global Group Membership Evaluations/sec; SAM GC Evaluations/sec; DRA Inbound Full Sync Objects Remaining; DRA Inbound Bytes Total/sec; DRA Inbound Bytes Not Compressed (Within Site)/sec; DRA Inbound Bytes Compressed (Between Sites, Before Compression)/sec; DRA Inbound Bytes Compressed (Between Sites, After Compression)/sec; DRA Outbound Bytes Total/sec; DRA Outbound Bytes Not Compressed (Within Site)/sec; DRA Outbound Bytes Compressed (Between Sites, Before Compression)/sec; DRA Outbound Bytes Compressed (Between Sites, After Compression)/sec; DS Client Binds/sec; DS Server Binds/sec; DS Client Name Translations/sec; DS Server Name Translations/sec; DS Security Descriptor Propagator Runtime Queue; DS Security Descriptor Propagator Average Exclusion Time; DRA Outbound Objects Filtered/sec; DRA Outbound Values Total/sec; DRA Outbound Values (DNs only)/sec; AB ANR/sec; AB Property Reads/sec; AB Searches/sec; AB Matches/sec; AB Proxy Lookups/sec; ATQ Threads Total; ATQ Threads LDAP; ATQ Threads Other; DRA Inbound Bytes Total Since Boot; DRA Inbound Bytes Not Compressed (Within Site) Since Boot; DRA Inbound Bytes Compressed (Between Sites, Before Compression) Since Boot; DRA Inbound Bytes Compressed (Between Sites, After Compression) Since Boot; DRA Outbound Bytes Total Since Boot; DRA Outbound Bytes Not Compressed (Within Site) Since Boot; DRA Outbound Bytes Compressed (Between Sites, Before Compression) Since Boot; DRA Outbound Bytes Compressed (Between Sites, After Compression) Since Boot; LDAP New Connections/sec; LDAP Closed Connections/sec; LDAP New SSL Connections/sec; DRA Pending Replication Operations; DRA Threads Getting NC Changes; DRA Threads Getting NC Changes Holding Semaphore; DRA Inbound Link Value Updates Remaining in Packet; DRA Inbound Total Updates Remaining in Packet; DS % Writes from NTDSAPI; DS % Searches from NTDSAPI; DS % Reads from NTDSAPI; SAM Account Group Evaluation Latency; SAM Resource Group Evaluation Latency; ATQ Outstanding Queued Requests; ATQ Request Latency; ATQ Estimated Queue Delay; Tombstones Garbage Collected/sec; Phantoms Cleaned/sec; Link Values Cleaned/sec; Tombstones Visited/sec; Phantoms Visited/sec; NTLM Binds/sec; Negotiated Binds/sec; Digest Binds/sec; Simple Binds/sec; External Binds/sec; Fast Binds/sec; Base searches/sec; Subtree searches/sec; Onelevel searches/sec; Database adds/sec; Database modifys/sec; Database deletes/sec; Database recycles/sec; Approximate highest DNT; Transitive operations/sec; Transitive suboperations/sec; Transitive operations milliseconds run
  423. interval = 10
  424. disabled = 0
  425. mode = single
  426. useEnglishOnly=true
  427. index = perfmon
  428.  
  429. [perfmon://DNS]
  430. object = DNS
  431. counters = Total Query Received; Total Query Received/sec; UDP Query Received; UDP Query Received/sec; TCP Query Received; TCP Query Received/sec; Total Response Sent; Total Response Sent/sec; UDP Response Sent; UDP Response Sent/sec; TCP Response Sent; TCP Response Sent/sec; Recursive Queries; Recursive Queries/sec; Recursive Send TimeOuts; Recursive TimeOut/sec; Recursive Query Failure; Recursive Query Failure/sec; Notify Sent; Zone Transfer Request Received; Zone Transfer Success; Zone Transfer Failure; AXFR Request Received; AXFR Success Sent; IXFR Request Received; IXFR Success Sent; Notify Received; Zone Transfer SOA Request Sent; AXFR Request Sent; AXFR Response Received; AXFR Success Received; IXFR Request Sent; IXFR Response Received; IXFR Success Received; IXFR UDP Success Received; IXFR TCP Success Received; WINS Lookup Received; WINS Lookup Received/sec; WINS Response Sent; WINS Response Sent/sec; WINS Reverse Lookup Received; WINS Reverse Lookup Received/sec; WINS Reverse Response Sent; WINS Reverse Response Sent/sec; Dynamic Update Received; Dynamic Update Received/sec; Dynamic Update NoOperation; Dynamic Update NoOperation/sec; Dynamic Update Written to Database; Dynamic Update Written to Database/sec; Dynamic Update Rejected; Dynamic Update TimeOuts; Dynamic Update Queued; Secure Update Received; Secure Update Received/sec; Secure Update Failure; Database Node Memory; Record Flow Memory; Caching Memory; UDP Message Memory; TCP Message Memory; Nbstat Memory; Unmatched Responses Received
  432. interval = 10
  433. disabled = 0
  434. mode = single
  435. useEnglishOnly=true
  436. index = perfmon
  437.  
  438.  
  439. ###### Perfmon Inputs from TA-AD/TA-DNS ######
  440. [perfmon://Processor]
  441. object = Processor
  442. counters = % Processor Time; % User Time; % Privileged Time; Interrupts/sec; % DPC Time; % Interrupt Time; DPCs Queued/sec; DPC Rate; % Idle Time; % C1 Time; % C2 Time; % C3 Time; C1 Transitions/sec; C2 Transitions/sec; C3 Transitions/sec
  443. instances = *
  444. interval = 10
  445. disabled = 1
  446. mode = multikv
  447. useEnglishOnly=true
  448.  
  449. [perfmon://Network_Interface]
  450. object = Network Interface
  451. counters = Bytes Total/sec; Packets/sec; Packets Received/sec; Packets Sent/sec; Current Bandwidth; Bytes Received/sec; Packets Received Unicast/sec; Packets Received Non-Unicast/sec; Packets Received Discarded; Packets Received Errors; Packets Received Unknown; Bytes Sent/sec; Packets Sent Unicast/sec; Packets Sent Non-Unicast/sec; Packets Outbound Discarded; Packets Outbound Errors; Output Queue Length; Offloaded Connections; TCP Active RSC Connections; TCP RSC Coalesced Packets/sec; TCP RSC Exceptions/sec; TCP RSC Average Packet Size
  452. instances = *
  453. interval = 10
  454. disabled = 1
  455. index = local
  456. mode = single
  457. useEnglishOnly=true
  458.  
  459. [perfmon://DFS_Replicated_Folders]
  460. object = DFS Replicated Folders
  461. counters = Bandwidth Savings Using DFS Replication; RDC Bytes Received; RDC Compressed Size of Files Received; RDC Size of Files Received; RDC Number of Files Received; Compressed Size of Files Received; Size of Files Received; Total Files Received; Deleted Space In Use; Deleted Bytes Cleaned up; Deleted Files Cleaned up; Deleted Bytes Generated; Deleted Files Generated; Updates Dropped; File Installs Retried; File Installs Succeeded; Conflict Folder Cleanups Completed; Conflict Space In Use; Conflict Bytes Cleaned up; Conflict Files Cleaned up; Conflict Bytes Generated; Conflict Files Generated; Staging Space In Use; Staging Bytes Cleaned up; Staging Files Cleaned up; Staging Bytes Generated; Staging Files Generated
  462. instances = *
  463. interval = 30
  464. disabled = 1
  465. mode = multikv
  466. useEnglishOnly=true
  467.  
  468. [perfmon://NTDS]
  469. object = NTDS
  470. counters = DRA Inbound Properties Total/sec; AB Browses/sec; DRA Inbound Objects Applied/sec; DS Threads in Use; AB Client Sessions; DRA Pending Replication Synchronizations; DRA Inbound Object Updates Remaining in Packet; DS Security Descriptor sub-operations/sec; DS Security Descriptor Propagations Events; LDAP Client Sessions; LDAP Active Threads; LDAP Writes/sec; LDAP Searches/sec; DRA Outbound Objects/sec; DRA Outbound Properties/sec; DRA Inbound Values Total/sec; DRA Sync Requests Made; DRA Sync Requests Successful; DRA Sync Failures on Schema Mismatch; DRA Inbound Objects/sec; DRA Inbound Properties Applied/sec; DRA Inbound Properties Filtered/sec; DS Monitor List Size; DS Notify Queue Size; LDAP UDP operations/sec; DS Search sub-operations/sec; DS Name Cache hit rate; DRA Highest USN Issued (Low part); DRA Highest USN Issued (High part); DRA Highest USN Committed (Low part); DRA Highest USN Committed (High part); DS % Writes from SAM; DS % Writes from DRA; DS % Writes from LDAP; DS % Writes from LSA; DS % Writes from KCC; DS % Writes from NSPI; DS % Writes Other; DS Directory Writes/sec; DS % Searches from SAM; DS % Searches from DRA; DS % Searches from LDAP; DS % Searches from LSA; DS % Searches from KCC; DS % Searches from NSPI; DS % Searches Other; DS Directory Searches/sec; DS % Reads from SAM; DS % Reads from DRA; DRA Inbound Values (DNs only)/sec; DRA Inbound Objects Filtered/sec; DS % Reads from LSA; DS % Reads from KCC; DS % Reads from NSPI; DS % Reads Other; DS Directory Reads/sec; LDAP Successful Binds/sec; LDAP Bind Time; SAM Successful Computer Creations/sec: Includes all requests; SAM Machine Creation Attempts/sec; SAM Successful User Creations/sec; SAM User Creation Attempts/sec; SAM Password Changes/sec; SAM Membership Changes/sec; SAM Display Information Queries/sec; SAM Enumerations/sec; SAM Transitive Membership Evaluations/sec; SAM Non-Transitive Membership Evaluations/sec; SAM Domain Local Group Membership Evaluations/sec; SAM Universal Group Membership Evaluations/sec; SAM Global Group Membership Evaluations/sec; SAM GC Evaluations/sec; DRA Inbound Full Sync Objects Remaining; DRA Inbound Bytes Total/sec; DRA Inbound Bytes Not Compressed (Within Site)/sec; DRA Inbound Bytes Compressed (Between Sites, Before Compression)/sec; DRA Inbound Bytes Compressed (Between Sites, After Compression)/sec; DRA Outbound Bytes Total/sec; DRA Outbound Bytes Not Compressed (Within Site)/sec; DRA Outbound Bytes Compressed (Between Sites, Before Compression)/sec; DRA Outbound Bytes Compressed (Between Sites, After Compression)/sec; DS Client Binds/sec; DS Server Binds/sec; DS Client Name Translations/sec; DS Server Name Translations/sec; DS Security Descriptor Propagator Runtime Queue; DS Security Descriptor Propagator Average Exclusion Time; DRA Outbound Objects Filtered/sec; DRA Outbound Values Total/sec; DRA Outbound Values (DNs only)/sec; AB ANR/sec; AB Property Reads/sec; AB Searches/sec; AB Matches/sec; AB Proxy Lookups/sec; ATQ Threads Total; ATQ Threads LDAP; ATQ Threads Other; DRA Inbound Bytes Total Since Boot; DRA Inbound Bytes Not Compressed (Within Site) Since Boot; DRA Inbound Bytes Compressed (Between Sites, Before Compression) Since Boot; DRA Inbound Bytes Compressed (Between Sites, After Compression) Since Boot; DRA Outbound Bytes Total Since Boot; DRA Outbound Bytes Not Compressed (Within Site) Since Boot; DRA Outbound Bytes Compressed (Between Sites, Before Compression) Since Boot; DRA Outbound Bytes Compressed (Between Sites, After Compression) Since Boot; LDAP New Connections/sec; LDAP Closed Connections/sec; LDAP New SSL Connections/sec; DRA Pending Replication Operations; DRA Threads Getting NC Changes; DRA Threads Getting NC Changes Holding Semaphore; DRA Inbound Link Value Updates Remaining in Packet; DRA Inbound Total Updates Remaining in Packet; DS % Writes from NTDSAPI; DS % Searches from NTDSAPI; DS % Reads from NTDSAPI; SAM Account Group Evaluation Latency; SAM Resource Group Evaluation Latency; ATQ Outstanding Queued Requests; ATQ Request Latency; ATQ Estimated Queue Delay; Tombstones Garbage Collected/sec; Phantoms Cleaned/sec; Link Values Cleaned/sec; Tombstones Visited/sec; Phantoms Visited/sec; NTLM Binds/sec; Negotiated Binds/sec; Digest Binds/sec; Simple Binds/sec; External Binds/sec; Fast Binds/sec; Base searches/sec; Subtree searches/sec; Onelevel searches/sec; Database adds/sec; Database modifys/sec; Database deletes/sec; Database recycles/sec; Approximate highest DNT; Transitive operations/sec; Transitive suboperations/sec; Transitive operations milliseconds run
  471. interval = 10
  472. disabled = 1
  473. mode = multikv
  474. useEnglishOnly=true
  475.  
  476. [perfmon://DNS]
  477. object = DNS
  478. counters = Total Query Received; Total Query Received/sec; UDP Query Received; UDP Query Received/sec; TCP Query Received; TCP Query Received/sec; Total Response Sent; Total Response Sent/sec; UDP Response Sent; UDP Response Sent/sec; TCP Response Sent; TCP Response Sent/sec; Recursive Queries; Recursive Queries/sec; Recursive Send TimeOuts; Recursive TimeOut/sec; Recursive Query Failure; Recursive Query Failure/sec; Notify Sent; Zone Transfer Request Received; Zone Transfer Success; Zone Transfer Failure; AXFR Request Received; AXFR Success Sent; IXFR Request Received; IXFR Success Sent; Notify Received; Zone Transfer SOA Request Sent; AXFR Request Sent; AXFR Response Received; AXFR Success Received; IXFR Request Sent; IXFR Response Received; IXFR Success Received; IXFR UDP Success Received; IXFR TCP Success Received; WINS Lookup Received; WINS Lookup Received/sec; WINS Response Sent; WINS Response Sent/sec; WINS Reverse Lookup Received; WINS Reverse Lookup Received/sec; WINS Reverse Response Sent; WINS Reverse Response Sent/sec; Dynamic Update Received; Dynamic Update Received/sec; Dynamic Update NoOperation; Dynamic Update NoOperation/sec; Dynamic Update Written to Database; Dynamic Update Written to Database/sec; Dynamic Update Rejected; Dynamic Update TimeOuts; Dynamic Update Queued; Secure Update Received; Secure Update Received/sec; Secure Update Failure; Database Node Memory; Record Flow Memory; Caching Memory; UDP Message Memory; TCP Message Memory; Nbstat Memory; Unmatched Responses Received
  479. interval = 10
  480. disabled = 1
  481. mode = multikv
  482. useEnglishOnly=true
  483.  
  484.  
  485. [admon://default]
  486. disabled = 1
  487. monitorSubtree = 1
  488.  
  489.  
  490. [WinRegMon://default]
  491. disabled = 1
  492. hive = .*
  493. proc = .*
  494. type = rename|set|delete|create
  495.  
  496. [WinRegMon://hkcu_run]
  497. disabled = 1
  498. hive = \\REGISTRY\\USER\\.*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
  499. proc = .*
  500. type = set|create|delete|rename
  501.  
  502. [WinRegMon://hklm_run]
  503. disabled = 1
  504. hive = \\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\.*
  505. proc = .*
  506. type = set|create|delete|rename
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement