Getting Data In

Will the Splunk System Driver be rebuilt with a non-obsolete DDK

Eng1
Engager

On Windows 2008 R2 x64 the SPLUNK Trace Kernel Mode Driver (splunkdrv-win6.sys - v6.0.6000.16386) shipped with Splunk Universal Forwarder 4.2.3 (build 105575) is listed as being built with the Windows Codename Longhorn DDK!!

Now this DDK was not meant for production driver builds and contained some major issues (which of course may not affect this driver), however when Microsoft released the supportd DDK all vendors are supposed to rebuild their drivers using this.

My question is did SPLUNK rebuild the Kernel Mode Driver with a production DDK, and if so which build of SPLUNK does it ship in and if not will you do a rebuild of this driver with a supported DDK?

komondor
New Member

I know this is an old thread but the issue seems to be back I am seeing an unsigned driver Splunk Network Kernel Mode Driver Windows Win 7 DDK provider. This is on Windows Server 2016 with secure boot enabled, (who wants and insecure boot for security software).

0 Karma

ahattrell_splun
Splunk Employee
Splunk Employee

This has been fixed in version 5 for Windows 7.

dwaddle
SplunkTrust
SplunkTrust

If this hasn't been fixed as of Splunk 4.3.2 (which is the current), I would recommend a support case regarding this.

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...