Splunk Enterprise

UF Batch Import Unreadable File Type Error

Path Finder

I have some SQL audit files  filename.sqlaudit that I want to import using batch. I have the configuration all done and working for test files like a .txt file, but the .sqlaudit file will not import.

Running '.\splunk.exe list inputstatus' give me 'type = unreadable file type'.

I have the Splunk Add-on for Microsoft SQL Server installed on the search head, so that should parse the file once it's imported, correct?

How do I get the UF to process the file?

Labels (1)
0 Karma

As I understand it, .sqlaudit files are binary rather than text, which is why Splunk won't read them.
If this reply helps you, an upvote would be appreciated.
0 Karma