Skip to main content
Announcements
Get Ready. A New Qlik Learning Experience is Coming February 17! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
Purushothaman
Partner - Creator III
Partner - Creator III

Guidance Needed: Appending AuditSecurity_Repository.txt and AuditActivity_Repository.txt Logs

Hi Qlik Experts,

I am currently working with two log files from Qlik Sense:

C:\ProgramData\Qlik\Sense\Log\Repository\Audit\AuditSecurity_Repository.txt
C:\ProgramData\Qlik\Sense\Log\Repository\Audit\AuditActivity_Repository.txt

We are using Splunk to extract logs from Qlik Sense for monitoring and analysis purposes. However, with the current setup, Splunk can only extract logs from a single file at a time, either AuditSecurity_Repository.txt or AuditActivity_Repository.txt.

To overcome this limitation, we considered appending the two files into one. However, upon reviewing the headers of both files, I noticed that they are not identical, as shown below:

Purushothaman_0-1725851130074.png


Given these differences, directly appending the files may not be advisable as it could create issues with data consistency and parsing in Splunk.

Could anyone please provide guidance on the best approach to handle this scenario? Whether it's a recommended method for merging the files or an alternative solution, your advice would be greatly appreciated.

Thank you in advance. 


0 Replies