splunk-winevtlog.exe
Sources: 300M+ executions observed in the wild.
Summary
Splunk Windows Event Log collector - reads and forwards Windows Event Logs to the Splunk indexer.
splunk-winevtlog.exe is the 302nd most commonly executed Windows program in EchoTrail's dataset, observed 33,001 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.
Get this in your tools
The same record for splunk-winevtlog.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/splunk-winevtlog.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Program Files\Splunk\bin99.89%
- C:\Program Files\SplunkUniversalForwarder\bin0.07%
- C:\Program Files\SUFwd\bin0.04%
Top Hashes (SHA256)
- 9376890cbe37aaff286a5d940ffed9df1230c96eeb09aac7af81da3460851b1e66.67%
- 4c74e55f4cfe4e4d58e5f13a529a92da62333cc503b768db6cfd78574a5d0fcd33.33%
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
- splunkd.exe100%
Top Children
- WerFault.exe100%
Security Analysis
What does splunk-winevtlog.exe normally do?
Helper process of the Splunk Universal Forwarder. Collects specific data types (AD, network, registry, event logs) and passes them to splunkd.exe for forwarding.
When is splunk-winevtlog.exe suspicious?
Running without a Splunk installation. Running from unexpected paths. Parent other than splunkd.exe.
False positive notes
Normal in environments with Splunk Universal Forwarder deployed.
Related Processes
Ask Rocky about splunk-winevtlog.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for splunk-winevtlog.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.