Getting Data In

Monitor Or MonitorNoHandle ?

nandhini_amir
Engager

Hi,
If one wants to import DNS query log on windows server,
Which is appropriate to use..? Monitor or MonitorNoHandle stanza.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'd use stream, actually, which can read them off the wire on the DNS. It's better and gets all the bad actors making broken requests that Windows throws away.

But to your question specifically - MonitorNoHandle seems perfect for this. Have you tried it? Does it do what you want? There's a list of reasons to use and to not use this in the docs for it. See especially the bottom - and how it won't read existing file contents and stuff.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...