Getting Data In

Remote Eventlog with wmi generates high CPU

CerielTjuh
Path Finder

Hi there,

I know that the best practice for high usage systems is a Splunk Forwarder but due to easy management my system administrators don't want any Splunk software on the machines and want to use WMI polling.

WMIprvse.exe takes up 20% of CPU on my Exchange server as soon as i turn on the Remote Eventlog polling. Is there a way to limit this or change this behaviour?

Thanks in advance!

Tags (1)
0 Karma
1 Solution

CerielTjuh
Path Finder

I have found an answer to all my questions.
Splunk generates a lot of CPU time on machines when polling with WMI.
This is not an issue at all, if a user or the system requires CPU time, the WMI service is suppressed and releases the CPU. When the process finishes and WMI gets CPU time all the eventlogs are collected and send to the central Splunk server.

You can check this out your self by running CPU Burn-in on the target machine (twice for a dual core machine).

View solution in original post

0 Karma

atx876
Explorer

We are trying to do the same, can you provide us some documentation on how you setup WMI? We are trying to collect from multiple windows clients joined to different DC. I cannot seem to find how i can pass various passwords via the WMI scripted inputs.

0 Karma

CerielTjuh
Path Finder

I have found an answer to all my questions.
Splunk generates a lot of CPU time on machines when polling with WMI.
This is not an issue at all, if a user or the system requires CPU time, the WMI service is suppressed and releases the CPU. When the process finishes and WMI gets CPU time all the eventlogs are collected and send to the central Splunk server.

You can check this out your self by running CPU Burn-in on the target machine (twice for a dual core machine).

0 Karma

CerielTjuh
Path Finder

As extra information:

The high CPU is caused by the Security Eventlog, my thoughts are to filter the events when querying for them, is that possible?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...