We recently updated 4 DEV servers with UniversalForwarder 10.0.0.0. However, on one of them the splunk-winevtlog.exe process consumes all memory and crashes the server within a few minutes of boot up. That one server that is crashing runs some java services, which may or may not be related. We're going to downgrade to UF 9.4.4.0 for now.
Thanks, we'll test out the fix you linked to.
@darrenWhat does the splunkd.log show after the UF has crashed?
Disabled the
evt_resolve_ad_obj = 0
in Splunk_TA_windows app , logs have now ceased.