<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I seeing Splunk-Winevtlog.exe Initial High CPU Utilization on Installation of Windows Splunk Forwarder v 7.1.2? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-Splunk-Winevtlog-exe-Initial-High-CPU/m-p/395880#M70596</link>
    <description>&lt;P&gt;At the time of initial startup, I think that the load is taken to acquire all past event logs.&lt;/P&gt;

&lt;P&gt;It will not happen unless we acquire the past.&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://&amp;lt;name&amp;gt;]
current_only = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart splunk.&lt;/P&gt;

&lt;P&gt;By setting current_only to 1 (enabled), you will get "only Windows event logs generated while Splunk is running".&lt;BR /&gt;
By default, it is set to 0 (invalid).&lt;/P&gt;</description>
    <pubDate>Mon, 19 Nov 2018 06:22:26 GMT</pubDate>
    <dc:creator>HiroshiSatoh</dc:creator>
    <dc:date>2018-11-19T06:22:26Z</dc:date>
    <item>
      <title>Why am I seeing Splunk-Winevtlog.exe Initial High CPU Utilization on Installation of Windows Splunk Forwarder v 7.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-Splunk-Winevtlog-exe-Initial-High-CPU/m-p/395879#M70595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Right after the initial install of the Splunk Windows Forwarder the &lt;STRONG&gt;Splunk-Winevtlog.exe&lt;/STRONG&gt; process consistently runs at 25% utilization.&lt;/P&gt;

&lt;P&gt;This will happen for &lt;STRONG&gt;3 to 5 hours&lt;/STRONG&gt; then will go down to zero and won't do it again.&lt;/P&gt;

&lt;P&gt;Wondering if anyone else may have seen this and how to prevent this from happening.&lt;/P&gt;

&lt;P&gt;The forwarders are being installed on Windows 10 devices.&lt;/P&gt;

&lt;P&gt;Thanks for all the help I'm getting on this forum. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Alan&lt;/P&gt;</description>
      <pubDate>Sun, 18 Nov 2018 23:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-Splunk-Winevtlog-exe-Initial-High-CPU/m-p/395879#M70595</guid>
      <dc:creator>ajdyer2000</dc:creator>
      <dc:date>2018-11-18T23:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing Splunk-Winevtlog.exe Initial High CPU Utilization on Installation of Windows Splunk Forwarder v 7.1.2?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-Splunk-Winevtlog-exe-Initial-High-CPU/m-p/395880#M70596</link>
      <description>&lt;P&gt;At the time of initial startup, I think that the load is taken to acquire all past event logs.&lt;/P&gt;

&lt;P&gt;It will not happen unless we acquire the past.&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://&amp;lt;name&amp;gt;]
current_only = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart splunk.&lt;/P&gt;

&lt;P&gt;By setting current_only to 1 (enabled), you will get "only Windows event logs generated while Splunk is running".&lt;BR /&gt;
By default, it is set to 0 (invalid).&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 06:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-Splunk-Winevtlog-exe-Initial-High-CPU/m-p/395880#M70596</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-11-19T06:22:26Z</dc:date>
    </item>
  </channel>
</rss>

