Getting Data In

Monitor Or MonitorNoHandle ?

nandhini_amir
Engager

Hi,
If one wants to import DNS query log on windows server,
Which is appropriate to use..? Monitor or MonitorNoHandle stanza.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'd use stream, actually, which can read them off the wire on the DNS. It's better and gets all the bad actors making broken requests that Windows throws away.

But to your question specifically - MonitorNoHandle seems perfect for this. Have you tried it? Does it do what you want? There's a list of reasons to use and to not use this in the docs for it. See especially the bottom - and how it won't read existing file contents and stuff.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...