Archive

Splunkd is filling the Security eventlog with Process creation messages

New Member

New Splunk user here:

We have an auditing requirement to audit process creation messages. It appears that the splunk service (Splunkd.exe) is
generating Process creation messages ( Eventid 4688 ) constantly in our security eventlog and the eventlogs are getting huge.

We are using version 6.1.

There must be others out there with this requirement. Are there any work arounds other than disabling auditing.. (which may not be possible)?

Tags (2)
0 Karma

Explorer

Bump! We're seeing the same issue as well, anyone have an update on this?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!