Other Usage

APPCRASH

Crescini
New Member

Hello,

Im getting several APPCRASH Event ID 1001.

Do we have a solution ? Below the entire error message :

Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0

Problem signature:
P1: splunk-perfmon.exe
P2: 2048.1280.24325.31539
P3: 5f057cc6
P4: splunk-perfmon.exe
P5: 2048.1280.24325.31539
P6: 5f057cc6
P7: c0000005
P8: 00000000009b5003
P9:
P10:

Attached files:
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBA61.tmp.WERInternalMetadata.xml

These files may be available here:
\\?\C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_splunk-perfmon.e_b6ce8fa2681eaf73929792a742cf0cc962c88_d85046b8_bc677b10

Analysis symbol:
Rechecking for solution: 0
Report Id: 0e443e45-f399-4d76-a355-2c805ed3a192
Report Status: 131172
Hashed bucket:
Cab Guid: 0

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Report it to Splunk Support.  They may have a solution available.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...