All Apps and Add-ons

Cannot get WMI event after to 8.5

peterchow
Explorer

Dear all,

I just upgraded splunk to 6.5. After finished, I find cannot get WMI event from other server. The splunk server and other server are in same domain. I checked the log and it show following message.

10-25-2016 11:01:34.544 +0800 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-wmi.exe"" WMI - Unable to connect to WMI namespace "\HQ1\root\cimv2" (attempt to connect took 29.00 milliseconds) (error="Access is denied." HRESULT=80070005)

Before upgrade, we created another credential for splunk to remote other server to get WMI event and it is work. However, it fail after upgrade to 6.5. May I know how to put those credential on splunk?

Tags (1)
0 Karma

alewkowicz
Explorer

Maybe your input is impacting by this issue :

http://docs.splunk.com/Documentation/Splunk/6.5.0/ReleaseNotes/KnownIssues

SPL-34347 = wmi input default fields - with value including newlines doesn't search properly becasue of \r\n issue

0 Karma

TStrauch
Communicator

Hi,

verify that the splunk run user have the permission to read wmi data. If the splunk run user is not a domain admin you must verify that it has the permission to gather wmi information.

for additional information read the docs.

http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/MonitorWindowseventlogdata

kind regards

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...