Splunk Search

What is splunkdrv?

Lowell
Super Champion

Can anyone explain the purpose and function of the "splunkdrv" Windows service? It appears as though this is some kind of kernel-mode driver. I'm curious what Splunk needs to do in kernel-mode that couldn't be done at user-level.

Tags (1)
0 Karma
1 Solution

rovechkin_splun
Splunk Employee
Splunk Employee

splunkdrv is kernel mode filter driver for Windows registry. Essentially it allows Splunk to listen to every call to registry and log it as a registry event. Windows implements its driver framework such that it allows such lightweight filter drivers to be plugged into existing drivers such as registry file system, etc.

View solution in original post

rovechkin_splun
Splunk Employee
Splunk Employee

splunkdrv is kernel mode filter driver for Windows registry. Essentially it allows Splunk to listen to every call to registry and log it as a registry event. Windows implements its driver framework such that it allows such lightweight filter drivers to be plugged into existing drivers such as registry file system, etc.

Get Updates on the Splunk Community!

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...

Want to Reduce Costs, Mitigate Risk, Improve Performance, or Increase Efficiencies? ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...