Splunk Enterprise

In UniversalForwarder 10.0.0.0, splunk-winevtlog.exe process consumes all memory and crashes the server

darren
Observer

We recently updated 4 DEV servers with UniversalForwarder 10.0.0.0.  However, on one of them the splunk-winevtlog.exe process consumes all memory and crashes the server within a few minutes of boot up.   That one server that is crashing runs some java services, which may or may not be related.  We're going to downgrade to UF 9.4.4.0 for now.

Labels (2)
0 Karma

darren
Observer

Thanks, we'll test out the fix you linked to.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@darrenWhat does the splunkd.log show after the UF has crashed?

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@darren 

Check this https://community.splunk.com/t5/Splunk-Enterprise/URGENT-All-splunk-forwarders-upgraded-to-10-0-vers... 

Disabled the

evt_resolve_ad_obj = 0

in Splunk_TA_windows app , logs have now ceased.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...