All Apps and Add-ons

Why am I getting splunk-MonitorNoHandle errors in the splunkd.log from domain controllers with universal forwarders installed?

cborgal
Explorer

Hi,

I'm receiving a bunch of splunk-MonitorNoHandle errors in the splunkd log. These errors are coming from domain controllers with the Universal Forwarder installed with apps Splunk_TA_windows, TA-DNSServer-NT6, and TA-DomainController-NT6. I can't seem to find anything online about these error messages and what they could mean. Does anyone have experience with these errors?

message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - DisplayError: The system cannot find the file specified.\r\n
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - StopDriver: Failed to get service handle 0x424
message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - runWinMonitorNoHandleMon: Could not connect to filter driver 0x80070002
0 Karma

ajacobi
Path Finder

I was getting these errors also. There is a file called SplunkMonitorNoHandledrv.inf in the bin directory. After i installed the file the errors were resolved and i was able to successfully monitor the DNS debug file

reedmohn
Communicator

Installing the inf file seems to have done the trick on our servers as well.

One thing we noted: most servers were OK, but some 2008 R2 servers were not.

Apart from that, it seems that it is Server 2012, and 2008 core / 2012 core that have failed to pick this up on their own.

0 Karma

ajacobi
Path Finder

I found that also. Half were ok but the other half had issues. At least it's a simple fix

0 Karma

reedmohn
Communicator

After i installed the file the errors
were resolved and i was able to
successfully monitor the DNS debug
file

What do you mean by "installed the file"? You say the file is already there. (...?)

0 Karma

ajacobi
Path Finder

It is already there. It is an inf file so you can right-click it and select install.

0 Karma

reedmohn
Communicator

Ah.. literally install it 🙂 I thought maybe you meant moving it to some specific folder. Tnx!

0 Karma

ajacobi
Path Finder

No worries mate. Hope it helps

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...