All Apps and Add-ons

Monitoring file which application 'locks' i.e. concurrent access causes application issues.

stanwin
Contributor

We have the log files on AS400 box.

Getting them out of server is not the query. Need to understand for an application JD Edwards that is holding 'read lock' on file.

To clarify it isnt a lock per say rather, If any 3rd party tool tries to read file (live log) than application will get issues/unstable due to multiple log file read .
Oracle has declined support for this stating wont support 3rd party integrations. .

Was wondering if anyone has had any experience dealing with such type of file monitoring scenarios.

Below are options :
-intermediate copies/FTP is not best option due to file rollouts?
-Syslog /other forwarding agents will read the file leading to issues mentioned.

thanks
Stanwin

Tags (1)
0 Karma
1 Solution

stanwin
Contributor

The solution for this is to FTP data onto intermediate server OR copy to different path where splunk can read them. .

In our case the application did not get affected if file was copied .

View solution in original post

0 Karma

stanwin
Contributor

The solution for this is to FTP data onto intermediate server OR copy to different path where splunk can read them. .

In our case the application did not get affected if file was copied .

0 Karma

pmdba
Builder

Have you looked at the AS/400 app for Splunk? There are a number of related questions on this site, as well.

0 Karma

stanwin
Contributor

It ONLY gets you AUDJRN data from the server, not actual application logs.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...