I am trying to read the audit logs in Splunk from SAP ABAP and JAVA.
1. The audit logs are in binary
2. I am able to read other logs from the file path except the audit logs
3. I have tried with NO_CHECK_BINARY= true in props.conf during input time, but no luck
4. The logs are sent via Universal Forwarder installed in the SAP instance(where the audit logs are stored), I am able to read the logs stored in the file path. Only audit logs are not read.
Please suggest how we can read the SAP ABAP and JAVA audit logs in splunk without "SAP PowerConnect for Splunk"
Note: I am using Splunk v.7.2.5.1
Thanks in advance!