<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125845#M25946</link>
    <description>&lt;P&gt;This problem was fixed in Splunk 6.3.0. I've personally verified it with Splunk 6.3.2 Universal Forwarder.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2016 20:52:37 GMT</pubDate>
    <dc:creator>jberd126</dc:creator>
    <dc:date>2016-01-06T20:52:37Z</dc:date>
    <item>
      <title>How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125844#M25945</link>
      <description>&lt;P&gt;Splunk appears to be calling "Win32_Product" WMI function that triggers a consistency check of installed applications causing numberous 1035 event codes to be generated in the event log (approximately 100 every 10 minutes). It appears to correlate nicely with perfmon queries.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;eventtype="wineventlog_windows" sourcetype="WinEventLog:*" EventCode=1035 SourceName=MsiInstaller 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I can confirm that, through PowerShell, executing "Get-WmiObject Win32_Product" does indeed trigger the 1035 events/&lt;/P&gt;

&lt;P&gt;I've looked through our configs and have verified that we are not running a Win32_Product WMI query explicitly and I verified that running the Splunk command 'splunk-wmi' does &lt;STRONG&gt;not&lt;/STRONG&gt; trigger the generation of 1035 events. &lt;/P&gt;

&lt;P&gt;Not all machines exhibit this problem and we have not been able to determine a pattern on why some are affected and others are not.&lt;/P&gt;

&lt;P&gt;Software&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Windows Server 2012 &lt;/LI&gt;
&lt;LI&gt;Splunk Universal Forwarder 6.2.2&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;More information in Microsoft KB article: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Event log message indicates that the Windows Installer reconfigured all installed applications: &lt;A href="https://support.microsoft.com/en-us/kb/974524"&gt;https://support.microsoft.com/en-us/kb/974524&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 29 May 2015 16:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125844#M25945</guid>
      <dc:creator>jberd126</dc:creator>
      <dc:date>2015-05-29T16:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125845#M25946</link>
      <description>&lt;P&gt;This problem was fixed in Splunk 6.3.0. I've personally verified it with Splunk 6.3.2 Universal Forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 20:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125845#M25946</guid>
      <dc:creator>jberd126</dc:creator>
      <dc:date>2016-01-06T20:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125846#M25947</link>
      <description>&lt;P&gt;Note that the every 10 minutes issue for us appears to be tied to WinHostMon stanzas. The default interval for WinHostMon is every 10 minutes. Procmon is currently set to every 1 minute for us so I don't believe this to be causing the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 16:06:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125846#M25947</guid>
      <dc:creator>fairje</dc:creator>
      <dc:date>2016-01-28T16:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125847#M25948</link>
      <description>&lt;P&gt;I have same problem. Applications Event logs are filled with multiple events with id 1035 generated by MsiInstaller. I upgraded Splunk from 7.0.0 to 7.3.1, still no use. We are running on Windows Server 2016. Any help would be much appreciated. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 10:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125847#M25948</guid>
      <dc:creator>mahantdesai</dc:creator>
      <dc:date>2019-08-07T10:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why Splunk is generating Eventcode=1035 events on our Splunk 6.2.2 Windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125848#M25949</link>
      <description>&lt;P&gt;We have problem with splunk generating multiple events with event id 1035 generated by MsiInstaller. I have upgraded Splunk from 7.0.0 to 7.3.1, still no use. We are running on Windows Server 2016. Any help would be much appreciated. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 10:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-Splunk-is-generating-Eventcode-1035/m-p/125848#M25949</guid>
      <dc:creator>mahantdesai</dc:creator>
      <dc:date>2019-08-07T10:24:13Z</dc:date>
    </item>
  </channel>
</rss>

