Getting Data In

Splunk does not collect WMI events

elusive
Splunk Employee
Splunk Employee

Splunk was collecting event before but suddenly it stopped collecting events. I have restarted Splunk several times. I see the following message being logged in splunkd.log:

11-02-2010 15:53:02.028 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-wmi.exe"" WMI - Unable to read from the WMI checkpoint storage: Error executing: select value from keyvaluepairs_t where primarykey=?1; Msg=unable to open database file
Tags (1)

elusive
Splunk Employee
Splunk Employee

Splunk stores the information regarding what it is monitoring in the wmi_checkpoint file that is stored in %SPLUNK_HOME%\var\lib\splunk\persistentstorage. The error is encountered when wmi_checkpoint is corrupted or inaccessible. Check the following:

  1. if you have virus scan enabled, stop it "completely" and see if this resolves the issue.

  2. Check if you have any permission issue. Make sure the account starting Splunk services has a full control to %SPLUNK_HOME% directory.

  3. If it is corrupted, once you move wmi_checkpoint from %SPLUNK_HOME%\var\lib\splunk\persistentstorage Splunk will reindex. Please note that this can cause Splunk to reindex Windows Event Log pulled via wmi.

If none of the above is identified as a problem, then contact Support by submitting diag and %SPLUNK_HOME%\var\lib\splunk\persistentstorage.

Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...