Getting Data In

Is it possible to convert binary AIX audit logs and send it to Splunk?

sunilsuresh
New Member

Dear Experts,

I am receiving this error: FileClassifierManager - The file '/audit/trail' is invalid. Reason: binary

I want to enable the audit logs in AIX server. By default audit logs are written as binary and i want read that binary and capture the ouptput from UF and send it to indexer. Please let me know if i can send binary files, convert as a log file and send it to splunk.

Thanks,

Sunil Suresh

0 Karma

woodcock
Esteemed Legend

Is the file actually binary? If it is, then you shouldn't send Splunk it directly; you need to convert it to plain text first. If the problem is that it is not binary, then just add NO_BINARY_CHECK = true to your props.conf file.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...