Getting Data In

Why am I seeing Splunk-Winevtlog.exe Initial High CPU Utilization on Installation of Windows Splunk Forwarder v 7.1.2?

ajdyer2000
Path Finder

Hi,

Right after the initial install of the Splunk Windows Forwarder the Splunk-Winevtlog.exe process consistently runs at 25% utilization.

This will happen for 3 to 5 hours then will go down to zero and won't do it again.

Wondering if anyone else may have seen this and how to prevent this from happening.

The forwarders are being installed on Windows 10 devices.

Thanks for all the help I'm getting on this forum. 🙂

Alan

0 Karma

HiroshiSatoh
Champion

At the time of initial startup, I think that the load is taken to acquire all past event logs.

It will not happen unless we acquire the past.

inputs.conf

[WinEventLog://<name>]
current_only = 1

Restart splunk.

By setting current_only to 1 (enabled), you will get "only Windows event logs generated while Splunk is running".
By default, it is set to 0 (invalid).

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...