<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Garbled Events in new Splunk installation on Debian in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Garbled-Events-in-new-Splunk-installation-on-Debian/m-p/56165#M10967</link>
    <description>&lt;P&gt;Apparently this issue is related to my installer.  When I did an installation using the GUI installer and specified the server and such that way in a RDP session instead of running the command, everything for that machine seems to be showing up correctly.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Aug 2011 21:41:40 GMT</pubDate>
    <dc:creator>mpmackenna</dc:creator>
    <dc:date>2011-08-10T21:41:40Z</dc:date>
    <item>
      <title>Garbled Events in new Splunk installation on Debian</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Garbled-Events-in-new-Splunk-installation-on-Debian/m-p/56164#M10966</link>
      <description>&lt;P&gt;I recently installed Splunk on Debian 6.  I created a TCP receiver on port 10000 and installed the Universal forwarder with this command.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;msiexec.exe /i \\server\Applications\Splunk\32\splunkforwarder-4.2.2-101277-x86-release.msi DEPLOYMENT_SERVER="splunk:10000" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /quiet  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am seeing events populate in my server installation but they appear to be garbled nonsense of some sort.  What do I need to do to make my Windows events show up correctly on my server.&lt;BR /&gt;
Here is an example of what I see when I click event and choose to see source.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\u0016\u0003\x00\x00D\u0001\x00\x00@\u0003\x00NB\xE6.*e\xF1\x83\u001cH\xBE\u000b\xA5m۫\xCF=5k\u00041\x95n\x00r\u0012\xFC\u0015pg\xB7\x00\x00\u0018\x009\x008\x005\x003\x002\x00/\x00\u0016\x00\u0013\x00
\x00\u0005\x00\u0004\x00\xFF\u0002\u0001\x00
\u0016\u0003\x00\x00D\u0001\x00\x00@\u0003\x00NB\xE6p\x89WD8=  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is a link to a &lt;A href="http://img825.imageshack.us/img825/9422/screenshotjw.jpg"&gt;screenshot&lt;/A&gt; of my events list.&lt;BR /&gt;&lt;BR /&gt;
This &lt;A href="http://splunk-base.splunk.com/answers/2422/why-are-some-of-the-events-garbled-with-x00"&gt;post&lt;/A&gt; seems to be related but from what I can tell the suggestion is how I have Splunk configured.&lt;BR /&gt;&lt;BR /&gt;
Thanks!&lt;BR /&gt;&lt;BR /&gt;
Mike&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2011 20:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Garbled-Events-in-new-Splunk-installation-on-Debian/m-p/56164#M10966</guid>
      <dc:creator>mpmackenna</dc:creator>
      <dc:date>2011-08-10T20:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Garbled Events in new Splunk installation on Debian</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Garbled-Events-in-new-Splunk-installation-on-Debian/m-p/56165#M10967</link>
      <description>&lt;P&gt;Apparently this issue is related to my installer.  When I did an installation using the GUI installer and specified the server and such that way in a RDP session instead of running the command, everything for that machine seems to be showing up correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2011 21:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Garbled-Events-in-new-Splunk-installation-on-Debian/m-p/56165#M10967</guid>
      <dc:creator>mpmackenna</dc:creator>
      <dc:date>2011-08-10T21:41:40Z</dc:date>
    </item>
  </channel>
</rss>

