Getting Data In

Splunk does not collect WMI events

elusive
Splunk Employee
Splunk Employee

Splunk was collecting event before but suddenly it stopped collecting events. I have restarted Splunk several times. I see the following message being logged in splunkd.log:

11-02-2010 15:53:02.028 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-wmi.exe"" WMI - Unable to read from the WMI checkpoint storage: Error executing: select value from keyvaluepairs_t where primarykey=?1; Msg=unable to open database file
Tags (1)

elusive
Splunk Employee
Splunk Employee

Splunk stores the information regarding what it is monitoring in the wmi_checkpoint file that is stored in %SPLUNK_HOME%\var\lib\splunk\persistentstorage. The error is encountered when wmi_checkpoint is corrupted or inaccessible. Check the following:

  1. if you have virus scan enabled, stop it "completely" and see if this resolves the issue.

  2. Check if you have any permission issue. Make sure the account starting Splunk services has a full control to %SPLUNK_HOME% directory.

  3. If it is corrupted, once you move wmi_checkpoint from %SPLUNK_HOME%\var\lib\splunk\persistentstorage Splunk will reindex. Please note that this can cause Splunk to reindex Windows Event Log pulled via wmi.

If none of the above is identified as a problem, then contact Support by submitting diag and %SPLUNK_HOME%\var\lib\splunk\persistentstorage.

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...