<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754504#M119779</link>
    <description>&lt;P&gt;We're seeing the same crashes and it started with 9.4.5. 10.0.0 didn't help and either did 10.0.1. Still crashing.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Oct 2025 20:01:47 GMT</pubDate>
    <dc:creator>Mike_Prest1</dc:creator>
    <dc:date>2025-10-20T20:01:47Z</dc:date>
    <item>
      <title>UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754176#M119722</link>
      <description>&lt;P&gt;After upgrading to UF 10.0 we see many &lt;STRONG&gt;Application Error (EventCode=1000)&lt;/STRONG&gt; crashes on a &lt;STRONG&gt;subset&lt;/STRONG&gt; of servers only. Faulting modules vary between &lt;STRONG&gt;KERNELBASE.dll&lt;/STRONG&gt; (system) and &lt;STRONG&gt;VCRUNTIME140.dll&lt;/STRONG&gt; (sometimes loaded from UF bin).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Examples&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Faulting app:&lt;/SPAN&gt; &lt;SPAN class=""&gt;splunk-winevtlog.exe&lt;/SPAN&gt; &lt;SPAN class=""&gt;2560.0&lt;/SPAN&gt;&lt;SPAN class=""&gt;.26759&lt;/SPAN&gt;&lt;SPAN class=""&gt;.23473&lt;/SPAN&gt; &lt;SPAN class=""&gt;Faulting module:&lt;/SPAN&gt; &lt;SPAN class=""&gt;KERNELBASE.dll&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.0&lt;/SPAN&gt;&lt;SPAN class=""&gt;.17763&lt;/SPAN&gt;&lt;SPAN class=""&gt;.7553&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exception code:&lt;/SPAN&gt; &lt;SPAN class=""&gt;0xeeab5254&lt;/SPAN&gt; &lt;SPAN class=""&gt;Path:&lt;/SPAN&gt; &lt;SPAN class=""&gt;C:\Windows\System32\KERNELBASE.dll&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Faulting app:&lt;/SPAN&gt; &lt;SPAN class=""&gt;splunk-winevtlog.exe&lt;/SPAN&gt; &lt;SPAN class=""&gt;2560.0&lt;/SPAN&gt;&lt;SPAN class=""&gt;.26759&lt;/SPAN&gt;&lt;SPAN class=""&gt;.23473&lt;/SPAN&gt; &lt;SPAN class=""&gt;Faulting module:&lt;/SPAN&gt; &lt;SPAN class=""&gt;VCRUNTIME140.dll&lt;/SPAN&gt; &lt;SPAN class=""&gt;14.42&lt;/SPAN&gt;&lt;SPAN class=""&gt;.34438&lt;/SPAN&gt;&lt;SPAN class=""&gt;.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Path:&lt;/SPAN&gt; &lt;SPAN class=""&gt;C:\Program&lt;/SPAN&gt; &lt;SPAN class=""&gt;Files\SplunkUniversalForwarder\bin\VCRUNTIME140.dll&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exception code:&lt;/SPAN&gt; &lt;SPAN class=""&gt;0xc0000005&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Questions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Does UF 10.0 &lt;STRONG&gt;ship and prefer its own&lt;/STRONG&gt; VCRUNTIME140.dll, or should it rely on &lt;STRONG&gt;system&lt;/STRONG&gt; VC++ Redistributable?&lt;BR /&gt;&lt;SPAN&gt;- Any &lt;/SPAN&gt;&lt;STRONG&gt;known compatibility issues&lt;/STRONG&gt;&lt;SPAN&gt; with specific &lt;/SPAN&gt;KERNELBASE.dll&lt;SPAN&gt; builds (e.g., Server 2019 17763.x) for &lt;/SPAN&gt;splunk-winevtlog.exe&lt;SPAN&gt;?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- What &lt;/SPAN&gt;&lt;STRONG&gt;VC++ Redistributable version&lt;/STRONG&gt;&lt;SPAN&gt; is required/recommended for UF 10.0 (x64/x86)? Any compatibility matrix?&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- Any &lt;/SPAN&gt;&lt;STRONG&gt;known bugs/hotfixes&lt;/STRONG&gt;&lt;SPAN&gt; for these crashes in UF 10.0?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Note: Problematic hosts seem to have &lt;STRONG&gt;older runtime builds&lt;/STRONG&gt; than the working ones. Thanks for any pointers/docs!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 18:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754176#M119722</guid>
      <dc:creator>krynol</dc:creator>
      <dc:date>2025-10-10T18:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754185#M119723</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271469"&gt;@krynol&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;try disabling Security resolution (&lt;/SPAN&gt;&lt;SPAN&gt;evt_resolve_ad_obj = 0&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;etc/apps/Splunk_TA_windows/local/inputs.conf

[WinEventLog://Security]
evt_resolve_ad_obj = 0&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;evt_resolve_ad_obj = &amp;lt;boolean&amp;gt;
* How the input should interact with Active Directory while indexing Windows
  Event Log events.
* If you set this setting to true, the input resolves the Active
  Directory Security IDentifier (SID) objects to their canonical names for
  a specific Windows Event Log channel.
* If you enable the setting, the rate at which the input reads events
  on high-traffic Event Log channels can decrease. Latency can also increase
  during event acquisition. This is due to the overhead involved in performing
  AD translations.
* When you set this setting to true, you can optionally specify the domain
  controller name or dns name of the domain to bind to with the 'evt_dc_name'
  setting. The input connects to that domain controller to resolve the AD
  objects.
* If you set this setting to false, the input does not attempt any resolution.
* Default: false (disabled) for all channels&lt;/PRE&gt;&lt;P&gt;Please check this documentation&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/High-CPU-and-Memory-Usage-After-Splunk-UF-10-Upgrade" target="_blank" rel="noopener"&gt;https://splunk.my.site.com/customer/s/article/High-CPU-and-Memory-Usage-After-Splunk-UF-10-Upgrade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 10:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754185#M119723</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-10-11T10:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754278#M119736</link>
      <description>&lt;P&gt;Thanks, but in my case, this doesn't solve the problem.&lt;/P&gt;&lt;P&gt;The only thing that helped was downgrading to version 9.4.3, and the errors disappeared. After I reinstalled 10.0.1, the problem no longer occurred.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 12:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754278#M119736</guid>
      <dc:creator>krynol</dc:creator>
      <dc:date>2025-10-14T12:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754504#M119779</link>
      <description>&lt;P&gt;We're seeing the same crashes and it started with 9.4.5. 10.0.0 didn't help and either did 10.0.1. Still crashing.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 20:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/754504#M119779</guid>
      <dc:creator>Mike_Prest1</dc:creator>
      <dc:date>2025-10-20T20:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/756397#M119967</link>
      <description>&lt;P&gt;in our case that solved the issue,&lt;/P&gt;&lt;P&gt;interesting side note - only UFs where high level of cross AD domain resolution happens were impacted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 03:18:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/756397#M119967</guid>
      <dc:creator>Andre_</dc:creator>
      <dc:date>2025-12-11T03:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: UF 10.0 — splunk-winevtlog.exe crashes in VCRUNTIME140.dll / KERNELBASE.dll (EventCode=1000)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/756398#M119968</link>
      <description>&lt;P&gt;is that fixed in 9.4.7?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 03:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-10-0-splunk-winevtlog-exe-crashes-in-VCRUNTIME140-dll/m-p/756398#M119968</guid>
      <dc:creator>Andre_</dc:creator>
      <dc:date>2025-12-11T03:18:39Z</dc:date>
    </item>
  </channel>
</rss>

