New Splunk user here:
We have an auditing requirement to audit process creation messages. It appears that the splunk service (Splunkd.exe) is
generating Process creation messages ( Eventid 4688 ) constantly in our security eventlog and the eventlogs are getting huge.
We are using version 6.1.
There must be others out there with this requirement. Are there any work arounds other than disabling auditing.. (which may not be possible)?
Bump! We're seeing the same issue as well, anyone have an update on this?