Getting Data In

Splunk does not collect WMI events

elusive
Splunk Employee
Splunk Employee

Splunk was collecting event before but suddenly it stopped collecting events. I have restarted Splunk several times. I see the following message being logged in splunkd.log:

11-02-2010 15:53:02.028 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-wmi.exe"" WMI - Unable to read from the WMI checkpoint storage: Error executing: select value from keyvaluepairs_t where primarykey=?1; Msg=unable to open database file
Tags (1)

elusive
Splunk Employee
Splunk Employee

Splunk stores the information regarding what it is monitoring in the wmi_checkpoint file that is stored in %SPLUNK_HOME%\var\lib\splunk\persistentstorage. The error is encountered when wmi_checkpoint is corrupted or inaccessible. Check the following:

  1. if you have virus scan enabled, stop it "completely" and see if this resolves the issue.

  2. Check if you have any permission issue. Make sure the account starting Splunk services has a full control to %SPLUNK_HOME% directory.

  3. If it is corrupted, once you move wmi_checkpoint from %SPLUNK_HOME%\var\lib\splunk\persistentstorage Splunk will reindex. Please note that this can cause Splunk to reindex Windows Event Log pulled via wmi.

If none of the above is identified as a problem, then contact Support by submitting diag and %SPLUNK_HOME%\var\lib\splunk\persistentstorage.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...