Getting Data In

How to resolve alert message from IT team regarding Splunkd on Windows: "Unusual behavior"..."scrape memory via LSASS"...?

shriganesh1987
Engager

I have installed Splunk on my office PC and I got a message from an IT engineer saying the following:

"We were alerted to unusual behavior from Splunkd on your machine. It attempted to scrape memory via LSASS and as such was terminated. Is this normal behavior for this application?"

Please let me know about this, otherwise I may have to remove Splunk from PC.

What I should know about this?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...