Usually first few line have issue, I suspect the Application still writing the log to the log file but splunk try to read the log file
Can we setup splunk to wait ?
Right. If you look at the url I posted you can see the solution -
Automatically at parsing ("indexing") time for any new data, in
[yoursourcetype] SEDCMD-remove_nulls = s/\\x00//g