<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WIndows DNS debug log becomes deleted in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32942#M5874</link>
    <description>&lt;P&gt;You should use MonitorNoHande input type instead of monitor since dns log component is very sensitive to file access collisions.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jan 2015 03:32:37 GMT</pubDate>
    <dc:creator>dstaulcu</dc:creator>
    <dc:date>2015-01-14T03:32:37Z</dc:date>
    <item>
      <title>WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32934#M5866</link>
      <description>&lt;P&gt;On a Windows 2008 domain controller, DNS debug logging enabled, so that queries can be captured by Splunk.  The DNS debug log is called "D:\dns-log\dns-log.txt"&lt;/P&gt;

&lt;P&gt;That file is being monitored by Splunk and it successfully is added to Splunk indexer.&lt;/P&gt;

&lt;P&gt;Problem:&lt;BR /&gt;
This log file keeps disappearing from its host after some number of hours or days.&lt;/P&gt;

&lt;P&gt;If we restart the Microsoft DNS service, the log file is recreated and Splunk resumes indexing, minus the lost period of time when the file was missing.&lt;/P&gt;

&lt;P&gt;Is there any way that the Splunk Universal Forwarder could be causing the file to be deleted?&lt;/P&gt;

&lt;P&gt;I have not yet enabled Windows file auditing because that is quite resource intensive on the host.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 14:42:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32934#M5866</guid>
      <dc:creator>realdridgespl</dc:creator>
      <dc:date>2013-05-14T14:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32935#M5867</link>
      <description>&lt;P&gt;If your inputs.conf stanza for this input is of the type&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://&amp;lt;path&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then this is non-destructive. If your inputs.conf stanza for this input is of the type&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[batch://&amp;lt;path&amp;gt;]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then this could be destructive, although such a stanza should also have the line&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;move_policy = sinkhole
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;to be properly destructive (e.g., index the file and delete it).&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 17:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32935#M5867</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2013-05-14T17:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32936#M5868</link>
      <description>&lt;P&gt;Thanks for the idea --  but we are not using that type of config.&lt;/P&gt;

&lt;P&gt;Ours is:&lt;/P&gt;

&lt;P&gt;[monitor://D:\dns-log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = WinEvtDns&lt;BR /&gt;
sourcetype = dns&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 17:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32936#M5868</guid>
      <dc:creator>realdridgespl</dc:creator>
      <dc:date>2013-05-14T17:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32937#M5869</link>
      <description>&lt;P&gt;Then this is a non-destructive monitor.&lt;/P&gt;

&lt;P&gt;Something else is removing your file.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2013 17:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32937#M5869</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2013-05-14T17:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32938#M5870</link>
      <description>&lt;P&gt;Did you ever find the answer to this? It is happening to me too. It seems to be when the log file reached its maximum size it is deleted and recreated and during this process the file creation fails.&lt;/P&gt;

&lt;P&gt;Perhaps it fails to recreate the file because Splunk has a file handle on it.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2013 22:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32938#M5870</guid>
      <dc:creator>JeremyHagan</dc:creator>
      <dc:date>2013-11-03T22:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32939#M5871</link>
      <description>&lt;P&gt;I came across interesting article when digging for info on the same subject - (not enough karma to paste the link) try googling for "Gathering detailed DNS debug logs from AD DNS" or go to godlessheathenmemoirs blog at blogspot dot com and look at August 2011 archive.&lt;/P&gt;

&lt;P&gt;Haven't tried the tricks myself yet (there are always other priorities) but it might help.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2013 11:17:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32939#M5871</guid>
      <dc:creator>flewenda</dc:creator>
      <dc:date>2013-11-15T11:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32940#M5872</link>
      <description>&lt;P&gt;I've already read the "godlessheathenmemoirs" article and the "0x80000000 Logs write-through transactions" setting is enabled in my environment. It hasn't made it any better.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2013 21:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32940#M5872</guid>
      <dc:creator>JeremyHagan</dc:creator>
      <dc:date>2013-11-17T21:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32941#M5873</link>
      <description>&lt;P&gt;Was you able to find a solution for you problem?  I think I may have a similiar issue.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2013 20:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32941#M5873</guid>
      <dc:creator>kmcconnell</dc:creator>
      <dc:date>2013-12-10T20:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: WIndows DNS debug log becomes deleted</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32942#M5874</link>
      <description>&lt;P&gt;You should use MonitorNoHande input type instead of monitor since dns log component is very sensitive to file access collisions.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2015 03:32:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WIndows-DNS-debug-log-becomes-deleted/m-p/32942#M5874</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2015-01-14T03:32:37Z</dc:date>
    </item>
  </channel>
</rss>

