All Apps and Add-ons

Why am I getting splunk-MonitorNoHandle errors in the splunkd.log from domain controllers with universal forwarders installed?

cborgal
Explorer

Hi,

I'm receiving a bunch of splunk-MonitorNoHandle errors in the splunkd log. These errors are coming from domain controllers with the Universal Forwarder installed with apps Splunk_TA_windows, TA-DNSServer-NT6, and TA-DomainController-NT6. I can't seem to find anything online about these error messages and what they could mean. Does anyone have experience with these errors?

message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - DisplayError: The system cannot find the file specified.\r\n
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - StopDriver: Failed to get service handle 0x424
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - runWinMonitorNoHandleMon: Could not connect to filter driver 0x80070002
0 Karma

ajacobi
Path Finder

I was getting these errors also. There is a file called SplunkMonitorNoHandledrv.inf in the bin directory. After i installed the file the errors were resolved and i was able to successfully monitor the DNS debug file

reedmohn
Communicator

Installing the inf file seems to have done the trick on our servers as well.

One thing we noted: most servers were OK, but some 2008 R2 servers were not.

Apart from that, it seems that it is Server 2012, and 2008 core / 2012 core that have failed to pick this up on their own.

0 Karma

ajacobi
Path Finder

I found that also. Half were ok but the other half had issues. At least it's a simple fix

0 Karma

reedmohn
Communicator

After i installed the file the errors
were resolved and i was able to
successfully monitor the DNS debug
file

What do you mean by "installed the file"? You say the file is already there. (...?)

0 Karma

ajacobi
Path Finder

It is already there. It is an inf file so you can right-click it and select install.

0 Karma

reedmohn
Communicator

Ah.. literally install it 🙂 I thought maybe you meant moving it to some specific folder. Tnx!

0 Karma

ajacobi
Path Finder

No worries mate. Hope it helps

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...