<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk-winevtlog.exe keeps crashing on Windows server 2022 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686573#M19320</link>
    <description>&lt;P&gt;Interesting, splunk support hasn't had any luck with my case yet. We've been attempting different things but no luck. I may throw in the towel and downgrade to 2019&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 14:09:43 GMT</pubDate>
    <dc:creator>RickyC</dc:creator>
    <dc:date>2024-05-06T14:09:43Z</dc:date>
    <item>
      <title>splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/658390#M17423</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have migrated a 9.0.4 HF from a Windows Server 2012 to a Window server 2022. The original connector was working fine, while the new one (with the same settings) keeps crashing. This is the error I got almors every minute on Application event viewer:&lt;/P&gt;&lt;PRE&gt;Faulting application name: splunk-winevtlog.exe, version: 2305.256.25832.56887, time stamp: 0x64e8dfcc&lt;BR /&gt;Faulting module name: ntdll.dll, version: 10.0.20348.1970, time stamp: 0x31881ea2&lt;BR /&gt;Exception code: 0xc0000374&lt;BR /&gt;Fault offset: 0x0000000000104909&lt;BR /&gt;Faulting process id: 0x1304&lt;BR /&gt;Faulting application start time: 0x01d9ed2bd5be870c&lt;BR /&gt;Faulting application path: C:\Program Files\Splunk\bin\splunk-winevtlog.exe&lt;BR /&gt;Faulting module path: C:\Windows\SYSTEM32\ntdll.dll&lt;BR /&gt;Report Id: 45c2b6fd-2c6e-484d-9602-eb948052101d&lt;BR /&gt;Faulting package full name: &lt;BR /&gt;Faulting package-relative application ID:&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to upgrade the HF to version 9.0.6 and then to version 9.1.1 but the error persist.&lt;/P&gt;&lt;P&gt;It seems to be caused by the inputs configured on&amp;nbsp;Splunk_TA_windows (version 8.7.0 installed). This is the enabled inputs that cause the issue:&lt;/P&gt;&lt;PRE&gt;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;blacklist1 = EventCode="4662" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;blacklist2 = EventCode="566" Message="Object Type:(?!\s*groupPolicyContainer)"&lt;BR /&gt;blacklist3 = 4656,4658,4690,5031,5140,5150,5151,5154,5155,5156,5157,5158,5159&lt;BR /&gt;renderXml = false&lt;BR /&gt;index = wineventlog&lt;BR /&gt;&lt;BR /&gt;###### Forwarded WinEventLogs (WEF) ######&lt;BR /&gt;[WinEventLog://ForwardedEvents]&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;## The addon supports only XML format for the collection of WinEventLogs using WEF, hence do not change the below renderXml parameter to false.&lt;BR /&gt;renderXml = true&lt;BR /&gt;host = WinEventLogForwardHost&lt;BR /&gt;index = wineventlog&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only solution I found is to disable the&amp;nbsp;ForwardedEvents input. This way the HF works as expected. I also tried to set current_only=1 on that input with no luck.&lt;/P&gt;&lt;P&gt;Does anyone knows if it's a know issue and how to troubleshoot this?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 08:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/658390#M17423</guid>
      <dc:creator>aleccese</dc:creator>
      <dc:date>2023-09-22T08:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/685881#M19273</link>
      <description>&lt;P&gt;Can we bump this? I'm running into same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/685881#M19273</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-04-29T18:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686207#M19290</link>
      <description>&lt;P&gt;A temporary workaround that worked for us was setting current_only to 1 and restarting the forwarder....&lt;/P&gt;&lt;P&gt;Splunk-wineventlog.exe still crashes and restarts, but it does at least read some events and send them before it does.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 18:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686207#M19290</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-02T18:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686216#M19294</link>
      <description>&lt;P&gt;I find it strange that the other Event Logs forward just fine and not crash. It's just when forwarding the "forwarded events".&amp;nbsp; We can't be the only people using windows even collectors to collect events and then forward them to splunk server.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 18:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686216#M19294</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-05-02T18:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686223#M19296</link>
      <description>&lt;P&gt;Yeah, we have&amp;nbsp;14 servers acting as our WEF environment all with the same UF version and conf&amp;nbsp; pushed out from central management/deployment. There are 6 that are Server 2016, 4 are Server 2019, and another 4 are Server 2022.&lt;/P&gt;&lt;P&gt;Only the Server 2022 boxes have this issue.&lt;/P&gt;&lt;P&gt;I've messed around with various .conf settings trying to bandaid it and only "current_only = 1" seems to make a difference&lt;/P&gt;&lt;P&gt;I've packed up procmon pml and .dmp files for support to look at... dunno if there's a fix possible.... I'll post back if I hear anything.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 19:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686223#M19296</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-02T19:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686224#M19297</link>
      <description>&lt;P&gt;Really? Only 2022. I may downgrade if that's the case. I have a support ticket working with splunk and so far no luck or mention of version conflict. I may downgrade and test.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 19:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686224#M19297</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-05-02T19:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686230#M19298</link>
      <description>&lt;P&gt;Yep Server 2022 was the only outlier for us. The issue was consistent across a few 9.x UF versions as well. 9.01, 9.1.0 and 9.2.1&lt;/P&gt;&lt;P&gt;All had the same behavior on Server 2022 but not older win server platforms. Honestly if my infrastructure wasn't already up and running on 2022 I'd downgrade to 2019.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 20:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686230#M19298</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-02T20:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686411#M19309</link>
      <description>&lt;P&gt;Anecdotal but I found a few other log shoveling vendors appeared to have similar issues with the Forwarded log and Server 2022. Agent crashing/restarting constantly, but they seem to have patched their problems already.&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/wazuh/wazuh/pull/20594" target="_blank"&gt;Fix Windows eventchannel forwarded events by nbertoldo · Pull Request #20594 · wazuh/wazuh (github.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/elastic/beats/issues/36020" target="_blank"&gt;[Winlogbeat] Repeated warnings · Issue #36020 · elastic/beats (github.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Interesting at least.&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2024 12:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686411#M19309</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-04T12:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686573#M19320</link>
      <description>&lt;P&gt;Interesting, splunk support hasn't had any luck with my case yet. We've been attempting different things but no luck. I may throw in the towel and downgrade to 2019&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 14:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/686573#M19320</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-05-06T14:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687263#M19370</link>
      <description>&lt;P&gt;According to Splunk on our case, version 9.2.2 will have a fix for this and it'll be released on 5/24.&lt;/P&gt;&lt;P&gt;They also have a custom build available that'll solve it were going to try next week.&lt;/P&gt;</description>
      <pubDate>Sat, 11 May 2024 20:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687263#M19370</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-11T20:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687270#M19371</link>
      <description>&lt;P&gt;One thing - 9.1 introduced the wec_event_format parameter for windows event inputs. It can cause your events to not be ingested at all if misconfigured but maybe it can cause other problems. You can fiddle with forwarded events format in subscription setting and adjust this parameter accordingly.&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 07:01:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687270#M19371</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-05-12T07:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687272#M19372</link>
      <description>&lt;P&gt;It's an interesting thought, though the same issue is occuring on 9.0.1 for me but on Server2022&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 10:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687272#M19372</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-12T10:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687345#M19380</link>
      <description>&lt;P&gt;Would of been nice for Splunk support to mention this.&amp;nbsp; I've had to move on and decommission Server 2022. Installed 2019 like you suggested and everything is working as it should.&amp;nbsp; Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 14:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687345#M19380</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-05-13T14:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687357#M19383</link>
      <description>&lt;P&gt;Well.... I appreciate you helping me confirm it's just 2022 &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 16:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/687357#M19383</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-13T16:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688888#M19469</link>
      <description>&lt;P&gt;Did you managed to try version 9.2.2 they provided? They also gave it to me but in my case it's not working. Now I don't have crashes but the splunk-winevtlog process keeps to move in "suspended" state in task manager. Actually almost nothing is collected from Forwarded Events...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 15:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688888#M19469</guid>
      <dc:creator>aleccese</dc:creator>
      <dc:date>2024-05-28T15:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688891#M19470</link>
      <description>&lt;P&gt;No, i downgraded my operating system to Server 2019 and everything started working.&amp;nbsp; Ran into a different issue afterwards unfortunately. Too much data was being forwarded and had to start using a heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 13:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688891#M19470</guid>
      <dc:creator>RickyC</dc:creator>
      <dc:date>2024-05-28T13:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688894#M19471</link>
      <description>&lt;P&gt;Unfortunately, support has been slow to get us a patched version or 9.2.2 ahead of it's general release. They said that 9.2.2 release was being pushed back. I dunno, still in a holding pattern on my end.&lt;/P&gt;&lt;P&gt;That's concerning to hear that it didn't work for you... the "suspended behavior" is what i'm seeing on the existing 9.2.1 version.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 14:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688894#M19471</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-28T14:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688900#M19472</link>
      <description>&lt;P&gt;So basically we moved from crashes (9.1) to process suspended (9.2)...I would prefer the first, at least something was collected. Thanks a lot for the feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 15:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688900#M19472</guid>
      <dc:creator>aleccese</dc:creator>
      <dc:date>2024-05-28T15:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688907#M19473</link>
      <description>&lt;P&gt;Haha yeah I guess so, fwiw I see both on ours... Some processes are suspended when they crash others just crash and vanish from task manager.&lt;/P&gt;&lt;P&gt;Truthfully i'm not sure what the difference is between that behavior is.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 17:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/688907#M19473</guid>
      <dc:creator>StevenD</dc:creator>
      <dc:date>2024-05-28T17:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: splunk-winevtlog.exe keeps crashing on Windows server 2022</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/712421#M21704</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;just to notify you that this issue has been deeply troubleshooted with customer support and finally the fix should be included in the future release of Splunk 9.4.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 08:56:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-winevtlog-exe-keeps-crashing-on-Windows-server-2022/m-p/712421#M21704</guid>
      <dc:creator>Numb78</dc:creator>
      <dc:date>2025-02-25T08:56:34Z</dc:date>
    </item>
  </channel>
</rss>

