All Apps and Add-ons

Why am I getting splunk-MonitorNoHandle errors in the splunkd.log from domain controllers with universal forwarders installed?

cborgal
Explorer

Hi,

I'm receiving a bunch of splunk-MonitorNoHandle errors in the splunkd log. These errors are coming from domain controllers with the Universal Forwarder installed with apps Splunk_TA_windows, TA-DNSServer-NT6, and TA-DomainController-NT6. I can't seem to find anything online about these error messages and what they could mean. Does anyone have experience with these errors?

message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - DisplayError: The system cannot find the file specified.\r\n
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - StopDriver: Failed to get service handle 0x424
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - runWinMonitorNoHandleMon: Could not connect to filter driver 0x80070002
0 Karma

ajacobi
Path Finder

I was getting these errors also. There is a file called SplunkMonitorNoHandledrv.inf in the bin directory. After i installed the file the errors were resolved and i was able to successfully monitor the DNS debug file

reedmohn
Communicator

Installing the inf file seems to have done the trick on our servers as well.

One thing we noted: most servers were OK, but some 2008 R2 servers were not.

Apart from that, it seems that it is Server 2012, and 2008 core / 2012 core that have failed to pick this up on their own.

0 Karma

ajacobi
Path Finder

I found that also. Half were ok but the other half had issues. At least it's a simple fix

0 Karma

reedmohn
Communicator

After i installed the file the errors
were resolved and i was able to
successfully monitor the DNS debug
file

What do you mean by "installed the file"? You say the file is already there. (...?)

0 Karma

ajacobi
Path Finder

It is already there. It is an inf file so you can right-click it and select install.

0 Karma

reedmohn
Communicator

Ah.. literally install it 🙂 I thought maybe you meant moving it to some specific folder. Tnx!

0 Karma

ajacobi
Path Finder

No worries mate. Hope it helps

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...