Splunk Enterprise

splunk-powershell.exe

prakashraja1999
Loves-to-Learn Everything

In the environment where Splunk is running, it is called "splunk-powershell.exe" The process is running.

What role does this process play? This executable file was in the following folder, When I looked up the property, there was no information. → C: \ Program Files \ SplunkUniversalForwarder \ bin \ Please tell me more about this process.

0 Karma

Stefanie
Builder

splunk-powershell.exe is used for some of the modular inputs for windows specific devices.

If you look in a inputs.conf on your Universal Forwarder, there are stanzas that start with [powershell://.............................] 

That is what splunk-powershell.exe references.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...