<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I configure props.conf for Splunk to index a binary .dat file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-props-conf-for-Splunk-to-index-a-binary-dat/m-p/226904#M44293</link>
    <description>&lt;P&gt;See this blog post&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2011/07/19/the-naughty-bits-how-to-splunk-binary-logfiles/"&gt;http://blogs.splunk.com/2011/07/19/the-naughty-bits-how-to-splunk-binary-logfiles/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2016 16:45:03 GMT</pubDate>
    <dc:creator>sundareshr</dc:creator>
    <dc:date>2016-08-11T16:45:03Z</dc:date>
    <item>
      <title>How do I configure props.conf for Splunk to index a binary .dat file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-props-conf-for-Splunk-to-index-a-binary-dat/m-p/226903#M44292</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Today I encountered a strange thing in Splunk.&lt;/P&gt;

&lt;P&gt;I have Splunk 6.4.1 running on a Linux server. &lt;/P&gt;

&lt;P&gt;I tried to index a .dat file using a Universal Forwarder (Windows 6.4.1) and see that no data coming in to Splunk. When I checked _internal log, I saw that the problem is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tail reader ignoring file due to binary
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I configured the UF, in inputs.conf I wrote the sourcetype for this file (let's call it: test_dat_file). In addition, I created props.conf with the appropriate configuration that included &lt;CODE&gt;NO_BINARY_CHECK = true&lt;/CODE&gt; (to force Splunk to index it).&lt;/P&gt;

&lt;P&gt;After a couple of tries, I thought maybe my configuration was not correct, so I copied the file to the Splunk server locally and monitored it (the default sourcetype for Splunk was "known_binary"). I hoped this would work, but unfortunately no.&lt;/P&gt;

&lt;P&gt;Sample line in the file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03/08/2016, 00:00:16:394, ip 10.10.10.10 CRC ERR -&amp;gt; Buffer : sc32425sdfvEOT324dsfsg Error 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(all the lines are the same)&lt;/P&gt;

&lt;P&gt;Maybe someone can help with this issue.&lt;/P&gt;

&lt;P&gt;Omer.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:37:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-props-conf-for-Splunk-to-index-a-binary-dat/m-p/226903#M44292</guid>
      <dc:creator>omerr</dc:creator>
      <dc:date>2020-09-29T10:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure props.conf for Splunk to index a binary .dat file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-props-conf-for-Splunk-to-index-a-binary-dat/m-p/226904#M44293</link>
      <description>&lt;P&gt;See this blog post&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2011/07/19/the-naughty-bits-how-to-splunk-binary-logfiles/"&gt;http://blogs.splunk.com/2011/07/19/the-naughty-bits-how-to-splunk-binary-logfiles/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 16:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-props-conf-for-Splunk-to-index-a-binary-dat/m-p/226904#M44293</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-08-11T16:45:03Z</dc:date>
    </item>
  </channel>
</rss>

