Getting Data In

Does Splunk use the MS Visual C++ Runtime library?

mctester
Communicator

Does Splunk uses the Visual C++ Runtime Library?

Since installing the Splunk agent, I have seen no less than two popup errors on one of our file servers (Event log entry: “Application popup: Microsoft Visual C++ Runtime Library : Runtime Error! Program: This application has requested the Runtime to terminate it in an unusual way. Please contact the application's support team for more information.”) which we’ve never seen before on these systems. I think the same message appeared on one or more systems, but there might be slightly different verbage.

The error message does not identify the program, so I can’t connect it directly to Splunk, but aside from a few Microsoft patches, that change is the only deviation in the past three weeks on this system.

Any insight is appreciated. Thanks!

Tags (3)
0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Yes, Splunk does use that library.

The error itself doesn't specify Splunk, so I wouldn't jump to the conclusion that it's a result of the installation straight away. If there was a system or an app error, I would expect to be caught in the Windows event logs also, have you checked those logs for the times when you saw these messages on-screen.

When Splunk fails to do something or gets an unexpected result from an operation, it will usually record that in it's own logs, so check out $SPLUNK_HOME/var/log/splunk/splunkd.log for the same time-periods and see if you spot any possibly related error events in there. While you're looking in the log directory, check and see if there are any crash logs either from splunkd or splunk search, it could also be related to those processes

View solution in original post

Mick
Splunk Employee
Splunk Employee

Yes, Splunk does use that library.

The error itself doesn't specify Splunk, so I wouldn't jump to the conclusion that it's a result of the installation straight away. If there was a system or an app error, I would expect to be caught in the Windows event logs also, have you checked those logs for the times when you saw these messages on-screen.

When Splunk fails to do something or gets an unexpected result from an operation, it will usually record that in it's own logs, so check out $SPLUNK_HOME/var/log/splunk/splunkd.log for the same time-periods and see if you spot any possibly related error events in there. While you're looking in the log directory, check and see if there are any crash logs either from splunkd or splunk search, it could also be related to those processes

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...