Getting Data In

Why is the svchost.exe process thrashes the CPU whenever Splunk is running?

despera
Splunk Employee
Splunk Employee

I have Splunk 4.0.10 64bit version running in Windows 2008 R2 64bit. I noticed that when Splunkd service is turned on, svchost.exe process for LocalServiceNetworkRestricted service is thrashing the CPU up to 95%?

Tags (3)

despera
Splunk Employee
Splunk Employee

This may have to do with Splunk WMI or Events data input services which uses windows hostname resolution. If the Windows machine where Splunk is installed has NetBIOS over TCP/IP configured to enabled under WINS tab in the "Advanced TCP/IP Settings", disabling it, if it's not needed, would stop CPU thrashing. Usually having DNS type resolution would suffice in place of WINS.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...