Getting Data In

How can we monitor binary log data in splunk? is invalid. Reason: binary

alexethier
Engager

I have a python script that read data from the stdin, convert the input and output human readable text to the stdout.
this is my current setup:

inputs.conf

[monitor:///var/account/pacct]
sourcetype = pacct_binary

props.conf

[pacct_binary]
invalid_cause = archive
unarchive_cmd = /opt/splunk/etc/apps/search/bin/pacct.py

I experimented with multiple configurations in inputs.conf and props.conf. No matter what I do I always get the following warning when splunk start and I don't see my sourcetype in splunk web gui.

WARN  FileClassifierManager - The file '/var/account/pacct' is invalid. Reason: binary
INFO  TailingProcessor - Ignoring file '/var/account/pacct' due to: binary

Anyone can post an exemple of a inputs.conf and props.conf that would let me load this binary file.

Best,

Alex

carmackd
Communicator

You can simply ignore the binary check as well using the following props attribute.

#******************************************************************************
# Binary file configuration
#******************************************************************************

NO_BINARY_CHECK = [true|false]
* When set to true, Splunk processes binary files.
* Can only be used on the basis of [<sourcetype>], or [source::<source>], not [host::<host>].
* Defaults to false (binary files are ignored).
0 Karma

Ayn
Legend

Is there a reason for using monitor for this? The best option imho would be to run your pacct.py script directly as a script input and have Splunk simply read its stdout.

0 Karma

alexethier
Engager

No real reason. I'm new to Splunk. Thank you for the script input suggestion.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...