Getting Data In

How to upload and use a directory of binary files

splunklearner12
Path Finder

Network traces are stored in hundreds of binary files in a directory.

How do I upload those files (they won't get updated)?
In the Splunk settings, I saw how to upload a single script- but not a full directory.
I'm using a single instance.

0 Karma
1 Solution

kmorris_splunk
Splunk Employee
Splunk Employee

Splunk supports ingesting ASCII / human-readable data. You could technically ingest the files, but it really wouldn't be anything understandable. If there is a way to convert the binary to ASCII, then you could use a scripted input to run a script against the binaries. The script could dump the ASCII output to a directory which you could then monitor.

As for monitoring a whole directory, take a look at the docs here: https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf

View solution in original post

0 Karma

splunklearner12
Path Finder

I no longer need to use those binary files, so I'm accepting the below answer to close the question.

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Splunk supports ingesting ASCII / human-readable data. You could technically ingest the files, but it really wouldn't be anything understandable. If there is a way to convert the binary to ASCII, then you could use a scripted input to run a script against the binaries. The script could dump the ASCII output to a directory which you could then monitor.

As for monitoring a whole directory, take a look at the docs here: https://docs.splunk.com/Documentation/Splunk/7.2.6/Data/Monitorfilesanddirectorieswithinputs.conf

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...