Getting Data In

Is it possible to convert binary AIX audit logs and send it to Splunk?

sunilsuresh
New Member

Dear Experts,

I am receiving this error: FileClassifierManager - The file '/audit/trail' is invalid. Reason: binary

I want to enable the audit logs in AIX server. By default audit logs are written as binary and i want read that binary and capture the ouptput from UF and send it to indexer. Please let me know if i can send binary files, convert as a log file and send it to splunk.

Thanks,

Sunil Suresh

0 Karma

woodcock
Esteemed Legend

Is the file actually binary? If it is, then you shouldn't send Splunk it directly; you need to convert it to plain text first. If the problem is that it is not binary, then just add NO_BINARY_CHECK = true to your props.conf file.

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...