Getting Data In

Splunk not monitoring IIS log due to Binary data

jchampagne
Path Finder

I'm having a problem getting Splunk to monitor an active IIS log. When I look at the SplunkD log, I see the following errors:

05-17-2012 16:55:52.503 -0400 WARN FileClassifierManager - The file 'D:\LOGS\MSFTPSVC1\ex120517.log' is invalid. Reason: binary
05-17-2012 16:55:52.503 -0400 INFO TailingProcessor - Ignoring file 'D:\LOGS\MSFTPSVC1\ex120517.log' due to: binary

When I open the log file, I see normal text, however there is a bunch of white space at the bottom of the file. I assume this has to due with IIS still writing to the file.

How can I get Splunk to read this active log file so we can get real-time data?

0 Karma

lguinn2
Legend

In props.conf, put

[iis*]
NO_BINARY_CHECK = true

This assumes that the "offending" file has a sourcetype that starts with iis. Feel free to substitute a source specification instead of the sourcetype.

lguinn2
Legend

Also, have you tried running btool on the forwarder -

$ cd /opt/splunkforwarder # or wherever you installed splunk

$ ./splunk btool props list iis --debug

or just

$ ./splunk btool props list --debug | more

0 Karma

lguinn2
Legend

Where did you put the props.conf?
On the UF or on the indexer?

0 Karma

jchampagne
Path Finder

I saw that as a possible solution on the Wiki and I tried to implement it....but it didn't seem to work for me.

This server has a Universal forwarder installed and didn't have a props.conf file by default. I created one for my source type and added the no binary check, but I got the same result.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...