Splunk Enterprise
Highlighted

UF Batch Import Unreadable File Type Error

Path Finder

I have some SQL audit files  filename.sqlaudit that I want to import using batch. I have the configuration all done and working for test files like a .txt file, but the .sqlaudit file will not import.

Running '.\splunk.exe list inputstatus' give me 'type = unreadable file type'.

I have the Splunk Add-on for Microsoft SQL Server installed on the search head, so that should parse the file once it's imported, correct?

How do I get the UF to process the file?

Labels (1)
0 Karma
Highlighted

Re: UF Batch Import Unreadable File Type Error

SplunkTrust
SplunkTrust
As I understand it, .sqlaudit files are binary rather than text, which is why Splunk won't read them.
---
If this reply helps you, an upvote would be appreciated.
0 Karma