Getting Data In

Is it normal behavior for a Windows universal forwarder to have multiple Splunk processes in a terminated state?

anoopambli
Communicator

Why does the universal forwarder generate many splunk.exe processes and terminate them? i have a plain installation of a UF on Windows servers. It is not configured to send anything to an indexer at this point. Every time I start the forwarder it is creating multiple splunk processes.

eg:
splunk-regmon.exe
splunk-netmon.exe
splunk-admon.exe
etc.

I've added the below entries in inputs to avoid starting them, but they still get generated and stays in a terminated state.

Is this normal? Are they getting created because of any standard start up check?

Inputs.conf file

[default]
host = FIDSLC011ADS

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 1

[script://$SPLUNK_HOME\bin\scripts\splunk-regmon.path] disabled = 1
[script://$SPLUNK_HOME\bin\scripts\splunk-admon.path] disabled = 1
[script://$SPLUNK_HOME\bin\scripts\splunk-netmon.path] disabled = 1
0 Karma

gjanders
SplunkTrust
SplunkTrust

Does this relate to another Splunk answer such as Why are these additional Splunk processes starting and stopping on Windows hosts configured with Uni... ?

Perhaps run:

splunk btool inputs list --debug

On the universal forwarder, if your in Windows 2008 you will need to run in an admin cmd window...
This should tell you if the disabled is working as expected or not...

0 Karma

Michael
Contributor

Same here, in 2017; v 6.5.3.

Have a deployed environment. Have dozens of systems getting a deployment package with regmon.path set with "disabled = 1" and yet they continue to generate millions of entries a day.

Still working the issue...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...