I have Splunk 4.0.10 64bit version running in Windows 2008 R2 64bit. I noticed that when Splunkd service is turned on, svchost.exe process for LocalServiceNetworkRestricted service is thrashing the CPU up to 95%?
This may have to do with Splunk WMI or Events data input services which uses windows hostname resolution. If the Windows machine where Splunk is installed has NetBIOS over TCP/IP configured to enabled under WINS tab in the "Advanced TCP/IP Settings", disabling it, if it's not needed, would stop CPU thrashing. Usually having DNS type resolution would suffice in place of WINS.