All Apps and Add-ons

Why am I getting splunk-MonitorNoHandle errors in the splunkd.log from domain controllers with universal forwarders installed?

cborgal
Explorer

Hi,

I'm receiving a bunch of splunk-MonitorNoHandle errors in the splunkd log. These errors are coming from domain controllers with the Universal Forwarder installed with apps Splunk_TA_windows, TA-DNSServer-NT6, and TA-DomainController-NT6. I can't seem to find anything online about these error messages and what they could mean. Does anyone have experience with these errors?

message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - DisplayError: The system cannot find the file specified.\r\n
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - StopDriver: Failed to get service handle 0x424
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - runWinMonitorNoHandleMon: Could not connect to filter driver 0x80070002
0 Karma

ajacobi
Path Finder

I was getting these errors also. There is a file called SplunkMonitorNoHandledrv.inf in the bin directory. After i installed the file the errors were resolved and i was able to successfully monitor the DNS debug file

reedmohn
Communicator

Installing the inf file seems to have done the trick on our servers as well.

One thing we noted: most servers were OK, but some 2008 R2 servers were not.

Apart from that, it seems that it is Server 2012, and 2008 core / 2012 core that have failed to pick this up on their own.

0 Karma

ajacobi
Path Finder

I found that also. Half were ok but the other half had issues. At least it's a simple fix

0 Karma

reedmohn
Communicator

After i installed the file the errors
were resolved and i was able to
successfully monitor the DNS debug
file

What do you mean by "installed the file"? You say the file is already there. (...?)

0 Karma

ajacobi
Path Finder

It is already there. It is an inf file so you can right-click it and select install.

0 Karma

reedmohn
Communicator

Ah.. literally install it 🙂 I thought maybe you meant moving it to some specific folder. Tnx!

0 Karma

ajacobi
Path Finder

No worries mate. Hope it helps

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...