<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AS400 for Splunk app:  How is data collected on the AS/400? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108682#M7624</link>
    <description>&lt;P&gt;I am interested in using Splunk's app for monitoring AS/400 logs.  Does anyone have examples of how they collect log data on the AS/400 and forward it to Splunk?  Thanks.&lt;/P&gt;

&lt;P&gt;Here's a link to the app:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/24097/splunk-for-as400-iseries"&gt;http://splunk-base.splunk.com/apps/24097/splunk-for-as400-iseries&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2011 19:33:53 GMT</pubDate>
    <dc:creator>elliot</dc:creator>
    <dc:date>2011-05-24T19:33:53Z</dc:date>
    <item>
      <title>AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108682#M7624</link>
      <description>&lt;P&gt;I am interested in using Splunk's app for monitoring AS/400 logs.  Does anyone have examples of how they collect log data on the AS/400 and forward it to Splunk?  Thanks.&lt;/P&gt;

&lt;P&gt;Here's a link to the app:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/24097/splunk-for-as400-iseries"&gt;http://splunk-base.splunk.com/apps/24097/splunk-for-as400-iseries&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2011 19:33:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108682#M7624</guid>
      <dc:creator>elliot</dc:creator>
      <dc:date>2011-05-24T19:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108683#M7625</link>
      <description>&lt;P&gt;CL has just been added to the app.  The scripts should help you provide FTP automation, as well as QAUDJRN exports.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2011 23:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108683#M7625</guid>
      <dc:creator>Ron_Naken</dc:creator>
      <dc:date>2011-06-09T23:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108684#M7626</link>
      <description>&lt;P&gt;Elliot, we are using a product to stream off our QAUDJRN, QHST, QSYSOPR messages off the iSeries our our central log collector via Syslog.&lt;/P&gt;

&lt;P&gt;Ron, here is a question for you.  Our plan is to import into Splunk.  Do you think there will be any issues to adapt to this app?  &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2012 20:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108684#M7626</guid>
      <dc:creator>dondky</dc:creator>
      <dc:date>2012-06-26T20:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108685#M7627</link>
      <description>&lt;P&gt;It should be fairly straightforward to make the QAUDJRN data work with the app, without having to rework any of the searches.  All the searches in the app make the assumption that the data was collected in the 'iseries' index.  All the fields in use by the app are reported on the intro page when you enter the app.  If your fields are named differently, just use FIELDALIAS or rename them to match those used by the app.  In this way, it should be an almost drop-in solution.  Note that the app was built around QAUDJRN data, so QHST and QSYSOPR won't appear in the canned reports.  Having the data come in via syslog will make it very easy to parse with Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2012 20:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108685#M7627</guid>
      <dc:creator>Ron_Naken</dc:creator>
      <dc:date>2012-06-26T20:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108686#M7628</link>
      <description>&lt;P&gt;Thanks Ron, I'll take a wack at configuring it in our test environment prior to indexing on production.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2012 17:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108686#M7628</guid>
      <dc:creator>dondky</dc:creator>
      <dc:date>2012-06-28T17:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108687#M7629</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;It says file is Binary?&lt;/P&gt;

&lt;P&gt;Asked as400 admin to set OUTFILFMT to&lt;BR /&gt;
*TYPE5&lt;/P&gt;

&lt;P&gt;Below is error in Splunk:&lt;/P&gt;

&lt;P&gt;04-08-2015 15:22:40.029 +0530 WARN&lt;BR /&gt;
FileClassifierManager - The file&lt;BR /&gt;
'D:AS400sample logsauditdta.txt' is&lt;BR /&gt;
invalid. Reason: binary 04-08-2015&lt;BR /&gt;
15:22:40.029 +0530 INFO&lt;BR /&gt;
TailingProcessor - Ignoring file&lt;BR /&gt;
'D:AS400sample logsauditdta.txt' due&lt;BR /&gt;
to: binary&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Got it! Now the app is populating many reports &amp;amp; data ingested.&lt;/P&gt;

&lt;P&gt;If Splunk identifies a non ASCI character in any event it will flag the file as binary and it will log an event in splunkd.log as follow:&lt;/P&gt;

&lt;P&gt;10-22-2012 17:53:21.734 +0000 INFO TailingProcessor - Ignoring file '/usr/local/rex/azkaban/logs/azkaban.log' due to: binary &lt;/P&gt;

&lt;P&gt;To identify non ASCI characters you can use the following linux command line. The non ASCI characters will be higlighted.&lt;/P&gt;

&lt;P&gt;grep --color='auto' -P -n -r "[x80-xff]" azkaban.log&lt;/P&gt;

&lt;P&gt;Solution:&lt;BR /&gt;
Use the "Binary file configuration" in props.conf as presented in the previous answer.&lt;/P&gt;

&lt;P&gt;NO_BINARY_CHECK = [true|false] &lt;BR /&gt;
* When set to true, Splunk processes binary files. &lt;BR /&gt;
* Can only be used on the basis of [], or [source::], not [host::]. &lt;BR /&gt;
* Defaults to false (binary files are ignored).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:28:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108687#M7629</guid>
      <dc:creator>stanwin</dc:creator>
      <dc:date>2020-09-28T19:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: AS400 for Splunk app:  How is data collected on the AS/400?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108688#M7630</link>
      <description>&lt;P&gt;Is there any filtration possible on the control scripts running on the AS/400 server? &lt;/P&gt;

&lt;P&gt;Production is currently outputting close to 24 Gigs a day !&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2015 12:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/AS400-for-Splunk-app-How-is-data-collected-on-the-AS-400/m-p/108688#M7630</guid>
      <dc:creator>stanwin</dc:creator>
      <dc:date>2015-07-09T12:43:29Z</dc:date>
    </item>
  </channel>
</rss>

