Getting Data In

Disable loading of splunk-regmon

Derek
Path Finder

Hi,

How can I stop the loading of splunk-regmon?

I'm getting these errors:

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-regmon.exe" --driver-path "C:\Program Files\Splunk\bin"" splunk-regmon - GetDriverHandle: Unable to install driver.

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-regmon.exe" --driver-path "C:\Program Files\Splunk\bin"" splunk-regmon - run_regmon: Failed to initialize Registry Monitor

I've tried to troubleshoot Antivirus etc but with no luck.

Thanks!

1 Solution

Genti
Splunk Employee
Splunk Employee

Derek,

If i remember correctly this is a bug that Splunk developers are working on. If memory serves right, this does not interfere with your daily splunk usage and performance and you should not worry about it

.gz

View solution in original post

Genti
Splunk Employee
Splunk Employee

Derek,

If i remember correctly this is a bug that Splunk developers are working on. If memory serves right, this does not interfere with your daily splunk usage and performance and you should not worry about it

.gz

Derek
Path Finder

If you don't have access to Splunk Web then in inputs.conf (etc/system/local) add:

[script://$SPLUNK_HOME\bin\scripts\splunk-regmon.path]
disabled = 1

Genti
Splunk Employee
Splunk Employee

btw, you can still disable that if you would like to.
Just go to: manager > data inputs > script and disable the "splunk-regmon.path"
This way at least you wont be bothered by those msg's

0 Karma

Derek
Path Finder

Thanks for the info. I've only noticed this happen on one machine out of many so far. Is this a bug in 4.1.x?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...