Monitoring Splunk

not able to read SAP ABAP and JAVA audit logs in Splunk

chaitali_1994
Engager

I am trying to read the audit logs in Splunk from SAP ABAP and JAVA.
1. The audit logs are in binary
2. I am able to read other logs from the file path except the audit logs
3. I have tried with NO_CHECK_BINARY= true in props.conf during input time, but no luck
4. The logs are sent via Universal Forwarder installed in the SAP instance(where the audit logs are stored), I am able to read the logs stored in the file path. Only audit logs are not read.

Please suggest how we can read the SAP ABAP and JAVA audit logs in splunk without "SAP PowerConnect for Splunk"

Note: I am using Splunk v.7.2.5.1

Thanks in advance!

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...