Refine your search:

I have Splunk 4.0.10 64bit version running in Windows 2008 R2 64bit. I noticed that when Splunkd service is turned on, svchost.exe process for LocalServiceNetworkRestricted service is thrashing the CPU up to 95%?

asked 13 Apr '10, 22:39

despera's gravatar image

despera
4114
accept rate: 0%

edited 11 Jun '10, 22:06

Ledio%20Ago's gravatar image

Ledio Ago ♦
6793615


One Answer:

This may have to do with Splunk WMI or Events data input services which uses windows hostname resolution. If the Windows machine where Splunk is installed has NetBIOS over TCP/IP configured to enabled under WINS tab in the "Advanced TCP/IP Settings", disabling it, if it's not needed, would stop CPU thrashing. Usually having DNS type resolution would suffice in place of WINS.

link

answered 13 Apr '10, 22:47

despera's gravatar image

despera
4114
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×433
×134
×60

Asked: 13 Apr '10, 22:39

Seen: 2,047 times

Last updated: 11 Jun '10, 22:06

Copyright © 2005-2012 Splunk Inc. All rights reserved.