Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

props.conf for SAP SAL / Splunk thinks it is binary

$
0
0
Hi, my props.conf for reading the SAP Security Audit Log looks like this: [sap:sal] category = Custom LINE_BREAKER=.()2AU CHARSET=utf-16be TIME_PREFIX=2AU. TIME_FORMAT=%Y%m%d%H%M%S SHOULD_LINEMERGE = false NO_BINARY_CHECK=1 But I get the following from tailreader: 05-27-2019 11:34:35.118 +0200 WARN FileClassifierManager - The file '/sapmnt/SAPK/audit/SAL/DS01/audit_01_20190527_000001' is invalid. Reason: binary. 05-27-2019 11:34:35.118 +0200 INFO TailReader - Ignoring file '/sapmnt/SAPK/audit/SAL/DS01/audit_01_20190527_000001' due to: binary Any ideas? thx afx

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>