We upgraded from 9.4.3 to 10.0 and now all the splunk forwarders are crashing because of the splunk-winevtlog service. How can I fix this? is there a fix? Is anyone else experiencing these issues?
I have had to disable all splunk instances because the service is a memory leak.
Disabled the
evt_resolve_ad_obj = 0
in Splunk_TA_windows app , logs have now ceased.
Disabled the
evt_resolve_ad_obj = 0
in Splunk_TA_windows app , logs have now ceased.