Splunk Search

Splunkd is filling the Security eventlog with Process creation messages

dbousquin
New Member

New Splunk user here:

We have an auditing requirement to audit process creation messages. It appears that the splunk service (Splunkd.exe) is
generating Process creation messages ( Eventid 4688 ) constantly in our security eventlog and the eventlogs are getting huge.

We are using version 6.1.

There must be others out there with this requirement. Are there any work arounds other than disabling auditing.. (which may not be possible)?

Tags (2)
0 Karma

spsponger2
Explorer

Bump! We're seeing the same issue as well, anyone have an update on this?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...