- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SPLUNK Universal Forwarder on Windows Server Core

KevinMurray
Explorer
02-06-2018
07:21 AM
I have several domain controllers, running the core version of Windows Server, reporting these errors in the splunkd logs:
01-30-2018 03:36:50.596 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"" splunk-regmon - startDriver - StartService failure for splunkdrv! Error = 201-30-2018 03:36:50.596 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"" splunk-regmon - WinRegistryMonitor::StartDriver: Unable to install driver.01-30-2018 03:36:50.596 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"" splunk-regmon - stopDriver - Service 'splunkdrv' could not be stopped! Error = 1062
01-30-2018 03:36:51.002 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
01-30-2018 03:36:51.002 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - runWinMonitorNoHandleMon: Could not connect to filter driver 0x80070002
01-30-2018 03:36:51.002 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - DisplayError: %01-30-2018 03:36:51.002 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"" splunk-monitornohandle - GetServiceHandle - OpenService failure for 'SplunkMonitorNoHandle'! Error = 1060
I would appreciate any help resolving these. I'm assuming since it is the "core" O/S, there is something locked down or missing that is required for SPLUNK to gather the data.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

dbot2001
Path Finder
02-19-2021
05:56 AM
Run "Repair' or reinstall the Splunk Application
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ansif
Motivator
02-06-2018
08:59 PM
For me a reboot helped.
You can also check the user permissions.
