Getting Data In

Is it possible to convert binary AIX audit logs and send it to Splunk?

sunilsuresh
New Member

Dear Experts,

I am receiving this error: FileClassifierManager - The file '/audit/trail' is invalid. Reason: binary

I want to enable the audit logs in AIX server. By default audit logs are written as binary and i want read that binary and capture the ouptput from UF and send it to indexer. Please let me know if i can send binary files, convert as a log file and send it to splunk.

Thanks,

Sunil Suresh

0 Karma

woodcock
Esteemed Legend

Is the file actually binary? If it is, then you shouldn't send Splunk it directly; you need to convert it to plain text first. If the problem is that it is not binary, then just add NO_BINARY_CHECK = true to your props.conf file.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...