splunk-wmi.exe

Summary

Remote Performance monitor using WMI

splunk-wmi.exe is the 3784th most commonly executed Windows program in EchoTrail's dataset, observed 42 times across enterprise environments. It typically runs from C:\Program Files\Splunk\bin and it is most often launched by splunkd.exe.

3784th
most commonly executed Windows program
42
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Program Files\Splunk\bin52.38%
  • C:\Program Files\SplunkUniversalForwarder\bin42.86%
  • C:\Program Files\SUFwd\bin4.76%

Top Hashes (SHA256)

  • 0466282f623514c375d6cf521e4c337b05a0d0c5a34c1992bed8b510a20a894d90%
  • 975e07e0f0b00c9e53e19b436c4d8dfbb87775736605edf66274850df2fb572210%

Process Ancestry

Top Grandparents

Top Parents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Ask Rocky about splunk-wmi.exe

Rocky answers questions about splunk-wmi.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.