splunk-winevtlog.exe

by Splunk / Cisco
SIEM / Log Collection

Summary

Splunk Windows Event Log collector - reads and forwards Windows Event Logs to the Splunk indexer.

splunk-winevtlog.exe is the 302nd most commonly executed Windows program in EchoTrail's dataset, observed 33,001 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.

302nd
most commonly executed Windows program
33,001
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Program Files\Splunk\bin99.89%
  • C:\Program Files\SplunkUniversalForwarder\bin0.07%
  • C:\Program Files\SUFwd\bin0.04%

Top Hashes (SHA256)

  • 9376890cbe37aaff286a5d940ffed9df1230c96eeb09aac7af81da3460851b1e66.67%
  • 4c74e55f4cfe4e4d58e5f13a529a92da62333cc503b768db6cfd78574a5d0fcd33.33%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does splunk-winevtlog.exe normally do?

Helper process of the Splunk Universal Forwarder. Collects specific data types (AD, network, registry, event logs) and passes them to splunkd.exe for forwarding.

When is splunk-winevtlog.exe suspicious?

Running without a Splunk installation. Running from unexpected paths. Parent other than splunkd.exe.

False positive notes

Normal in environments with Splunk Universal Forwarder deployed.

Related Processes

Ask Rocky about splunk-winevtlog.exe

Rocky answers questions about splunk-winevtlog.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.