Splunkd is filling the Security eventlog with Process creation messages

New Member

New Splunk user here:

We have an auditing requirement to audit process creation messages. It appears that the splunk service (Splunkd.exe) is
generating Process creation messages ( Eventid 4688 ) constantly in our security eventlog and the eventlogs are getting huge.

We are using version 6.1.

There must be others out there with this requirement. Are there any work arounds other than disabling auditing.. (which may not be possible)?

Tags (2)
0 Karma


Bump! We're seeing the same issue as well, anyone have an update on this?

0 Karma