Splunk® Supported Add-ons

Splunk Add-on for Microsoft Hyper-V

Source types for the Splunk Add-on for Microsoft Hyper-V

The Splunk Add-on for Microsoft Hyper-V provides the index-time and search-time knowledge for Hyper-V inventory, performance metrics and alert data in the following formats.

Data source Source type Description CIM data models ITSI data models
Powershell Sourcetype microsoft:hyperv:vm Microsoft Hyper-V virtual machines (basic inventory). Inventory, Performance Virtualization
microsoft:hyperv:vm:ext Microsoft Hyper-V virtual machines (extended inventory).
microsoft:hyperv:vm:disk Microsoft Hyper-V virtual machine storage data.
microsoft:hyperv:vm:network Microsoft Hyper-V virtual machine network interface data.
microsoft:hyperv:host Microsoft Hyper-V host servers (basic inventory).
microsoft:hyperv:host:ext Microsoft Hyper-V host servers (extended inventory)
microsoft:hyperv:host:switch Microsoft Hyper-V host switch
microsoft:hyperv:perf:host Microsoft Hyper-V host performance
microsoft:hyperv:perf:datastore Microsoft Hyper-V datastore performance
microsoft:hyperv:perf:vm Microsoft Hyper-V VM performance.
Performance Monitor Sourcetype perfmon:HyperV_Hypervisor Microsoft Hyper-V Hypervisor Perfmon CounterSet List (Information on the hypervisor).
perfmon:HyperV_Logical_Processor Microsoft Hyper-V Hypervisor Logical Processor CounterSet List (Information on virtual processors)
perfmon:HyperV_Root_Processor Microsoft Hyper-V Hypervisor Root Virtual Processor CounterSet List (Information on virtual processors)
perfmon:HyperV_Virtual_Processor Microsoft Hyper-V Hypervisor Virtual Processor Perfmon CounterSet List (Information on virtual processors) Performance None
perfmon:HyperV_Partition Microsoft Hyper-V Hypervisor Partition Perfmon Counter List (Information on virtual machines)
perfmon:HyperV_Root_Partition Microsoft Hyper-V Hypervisor Root Partition Perfmon Counter List (Information on virtual machines)
perfmon:HyperV_VM_VID_Partition Microsoft Hyper-V VM VID Partition Perfmon Counter List (These are the perf counters for a VID partition object)
perfmon:HyperV_Virtual_Switch Microsoft Hyper-V Virtual Switch Perfmon Counter List (This counter set represents the statistics for the Microsoft Hyper-V switch.)
perfmon:HyperV_VM_Health Microsoft Hyper-V Virtual Machine Health Summary Perfmon Counter List (This counter set represents the health summary statistics for the Virtual Machine Management Service.)
perfmon:HyperV_VM_Summary Microsoft Hyper-V Virtual Machine Summary Perfmon Counter List
perfmon:HyperV_Network Microsoft Hyper-V Network Adapter Perfmon Counter List (This counter set represents the statistics for the Microsoft Hyper-V network adapter) Performance
perfmon:HyperV_Virtual_Storage_Device Microsoft Hyper-V Virtual Storage Device Perfmon Counter List (This counter set represents the statistics for a virtual storage device.)
perfmon:HyperV_Legacy_Network Microsoft Hyper-V Network Adapter Perfmon Counter List (This counter set represents the statistics for the Microsoft Hyper-V network adapter).
Windows event log sourcetype WinEventLog:Microsoft-Windows-Hyper-V-Config-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Config-Admin Change
WinEventLog:Microsoft-Windows-Hyper-V-Config-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Config-Operational
WinEventLog:Microsoft-Windows-Hyper-V-Hypervisor-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Hypervisor-Admin
WinEventLog:Microsoft-Windows-Hyper-V-Hypervisor-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Hypervisor-Operational
WinEventLog:Microsoft-Windows-Hyper-V-Image-Management-Service-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Image-Management-Service-Admin
WinEventLog:Microsoft-Windows-Hyper-V-Image-Management-Service-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Image-Management-Service-Operational
WinEventLog:Microsoft-Windows-Hyper-V-Intergration-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Intergration-Admin
WinEventLog:Microsoft-Windows-Hyper-V-Network-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Network-Admin
WinEventLog:Microsoft-Windows-Hyper-V-Network-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Network-Operational
WinEventLog:Microsoft-Windows-Hyper-V-SynthNic-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-SynthNic-Admin
WinEventLog:Microsoft-Windows-Hyper-V-SynthNic-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-SynthNic-Operational
WinEventLog:Microsoft-Windows-Hyper-V-VMMS-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-VMMS-Admin
WinEventLog:Microsoft-Windows-Hyper-V-Worker-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Worker-Admin
WinEventLog:Microsoft-Windows-Hyper-V-SynthStor-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-SynthStor-Admin
WinEventLog:Microsoft-Windows-Hyper-V-SynthStor-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-SynthStor-Operational
WinEventLog:Microsoft-Windows-Hyper-V-Compute-Admin Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-Compute-Admin
WinEventLog:Microsoft-Windows-Hyper-V-VmSwitch-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-VmSwitch-Operational
WinEventLog:Microsoft-Windows-Hyper-V-VMMS-Networking Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-VMMS-Networking
WinEventLog:Microsoft-Windows-Hyper-V-VMMS-Operational Windows Events from Windows Event Log - Microsoft-Windows-Hyper-V-VMMS-Operational
Last modified on 29 July, 2021
Troubleshoot the Splunk Add-on for Microsoft Hyper-V   Release notes for the Splunk Add-on for Microsoft Hyper-V

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters