Monitoring Splunk

Monitoring Remote log via file share but have \x00\

kennethyeung
New Member

usually the first few line have issue, i suspect the application still writing the log file but splunk already try to read it.

====================================================================================
\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00

Date: 2018-12-20T00:00:00.146Z

Fields: date-time,client-ip,client-hostname,server-ip,server-hostname,source-context,connector-id,source,event-id,internal-message-id,message-id,recipient-address,recipient-status,total-bytes,recipient-count,related-recipient-address,reference,message-subject,sender-address,return-path,message-info,directionality,tenant-id,original-client-ip,original-server-ip,custom-data

====================================================================================

Any method to fix it or let splunk wait the application finish writing first

Tags (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!