Getting Data In

Why is the svchost.exe process thrashes the CPU whenever Splunk is running?

despera
Splunk Employee
Splunk Employee

I have Splunk 4.0.10 64bit version running in Windows 2008 R2 64bit. I noticed that when Splunkd service is turned on, svchost.exe process for LocalServiceNetworkRestricted service is thrashing the CPU up to 95%?

Tags (3)

despera
Splunk Employee
Splunk Employee

This may have to do with Splunk WMI or Events data input services which uses windows hostname resolution. If the Windows machine where Splunk is installed has NetBIOS over TCP/IP configured to enabled under WINS tab in the "Advanced TCP/IP Settings", disabling it, if it's not needed, would stop CPU thrashing. Usually having DNS type resolution would suffice in place of WINS.

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...