Getting Data In

High consumption POWERSHELL in Active Directory without related processes Splunk-Powershell.

hcarvcamp
Explorer

Hi, everyone

I have a simple PowerShell script that runs every 5 minutes grabbing data from a database.
I have noticed the memory climbs quite high (almost 4GB). I have an "output" is the Heavy Forwarder. Seems like the memory keeps climbing.

Print below, the processes:

alt text

Any suggestions?

Thank you,

Hugo Campelo.
_

spayneort
Contributor

Are you running the ad-repl-stat.ps1 script on Windows Server 2012 R2?

http://blogs.splunk.com/2014/01/13/active-directory-replication-and-windows-server-2012-r2/

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure the offending powershell process is related to Splunk. Not to be alarmist, but some ransomware use powershell to encrypt files.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hcarvcamp
Explorer

Rich,

When i STOP the UF, the highest consumption "die", and, back to the "normal" consumption.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That would seem to confirm it's Splunk-related.

---
If this reply helps you, Karma would be appreciated.
0 Karma

hcarvcamp
Explorer

Yeah,

But do you have any idea what can be?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...