<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to stop getting garbage HEXA ASCII logs from log source? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646016#M109901</link>
    <description>&lt;P&gt;Hi SMEs,&lt;/P&gt;
&lt;P&gt;I am getting some garbage/hexa format/ASCII format logs from one of the log source integrated with Splunk, it is customized linux platform and been integrated using TCP input. Sharing the sample log below. Seeking suggestions to find and fix it. thanks in advance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pm2012_0-1686118951686.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25723i479831E5EABA0EB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pm2012_0-1686118951686.png" alt="pm2012_0-1686118951686.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 19:25:51 GMT</pubDate>
    <dc:creator>pm2012</dc:creator>
    <dc:date>2023-06-07T19:25:51Z</dc:date>
    <item>
      <title>How to stop getting garbage HEXA ASCII logs from log source?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646016#M109901</link>
      <description>&lt;P&gt;Hi SMEs,&lt;/P&gt;
&lt;P&gt;I am getting some garbage/hexa format/ASCII format logs from one of the log source integrated with Splunk, it is customized linux platform and been integrated using TCP input. Sharing the sample log below. Seeking suggestions to find and fix it. thanks in advance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pm2012_0-1686118951686.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25723i479831E5EABA0EB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pm2012_0-1686118951686.png" alt="pm2012_0-1686118951686.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 19:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646016#M109901</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2023-06-07T19:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646020#M109903</link>
      <description>&lt;P&gt;How have you configured the input?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 06:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646020#M109903</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-07T06:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646022#M109904</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; Input are configured using TCP at HF and logs are being sent using rsyslog.conf input parameters having needed filename. Logs are being sent to customized TCP port 615xx. Created multiple inputs for each filepath defined in rsyslog.conf&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 06:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646022#M109904</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2023-06-07T06:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646031#M109905</link>
      <description>&lt;P&gt;Please can you share the config?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 07:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646031#M109905</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-07T07:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646036#M109906</link>
      <description>&lt;P&gt;Here is the rsyslog.conf file appended config, where 10.10.10.10 is Splunk HF IP and defined ports being used for log collection against TCP inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;##############Splunk#############&lt;/P&gt;&lt;P&gt;$InputFileName /var/SharedStorage/dl_logs/hostname01.com/dl_security/*&lt;BR /&gt;$InputFileTag dl-dl_security-log&lt;BR /&gt;$InputFileStateFile dl-dl_security-log&lt;BR /&gt;$InputFileSeverity error&lt;BR /&gt;$InputFileFacility local9&lt;BR /&gt;$InputRunFileMonitor&lt;BR /&gt;&lt;BR /&gt;$InputFileName /var/SharedStorage/dl_logs/hostname01.com/pacemaker/*&lt;BR /&gt;$InputFileTag dl-pacemaker-log&lt;BR /&gt;$InputFileStateFile dl-pacemaker-log&lt;BR /&gt;$InputFileSeverity error&lt;BR /&gt;$InputFileFacility local9&lt;BR /&gt;$InputRunFileMonitor&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;$InputFilePollInterval 10&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;$template cmdlogsTemplate,"&amp;lt;dl&amp;gt; %timereported:::date-year%-%timereported:::date-month%-%timereported:::date-day% %timereported:::date-hour%:%timereported:::date-minute%:%timereported:::date-second% %HOSTNAME% %syslogtag% %msg% \n "&lt;BR /&gt;&lt;BR /&gt;if $programname == 'dl-dl_security-log' then @@10.10.10.10:61515;cmdlogsTemplate&lt;BR /&gt;&amp;amp; ~&lt;BR /&gt;if $programname == 'dl-pacemaker-log' then @@10.10.10.10:61516;cmdlogsTemplate&lt;/P&gt;&lt;P&gt;*.* @@10.10.10.10:61500&lt;BR /&gt;#########################&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 07:51:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646036#M109906</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2023-06-07T07:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646056#M109908</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I suppose that your source file contains UTF16-LE characters? If so you must add encoding information to props.conf on HF side.&lt;/P&gt;&lt;P&gt;Here is couple of old answers which clarify this quite well&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Seing-null-x00-bytes-in-indexed-data-from-log-file-in-Windows/m-p/102824" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Seing-null-x00-bytes-in-indexed-data-from-log-file-in-Windows/m-p/102824&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Splunk-indexes-text-file-in-binary-format/m-p/61677" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Splunk-indexes-text-file-in-binary-format/m-p/61677&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 09:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646056#M109908</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-07T09:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646096#M109914</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just last doubt, how to check which format is it and which is supposed to be like UTF-18 or something else&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pm2012_0-1686137568328.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25733i5F791AB7ADA97ECB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pm2012_0-1686137568328.png" alt="pm2012_0-1686137568328.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 11:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646096#M109914</guid>
      <dc:creator>pm2012</dc:creator>
      <dc:date>2023-06-07T11:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting garbage HEXA ASCII logs from log source</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646103#M109918</link>
      <description>&lt;P&gt;You can use command file in linux see:&amp;nbsp;&lt;A href="https://www.shellhacks.com/linux-check-change-file-encoding/" target="_blank"&gt;https://www.shellhacks.com/linux-check-change-file-encoding/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Usually Splunk wants to use UTF-8 encoding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 12:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-stop-getting-garbage-HEXA-ASCII-logs-from-log-source/m-p/646103#M109918</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-07T12:34:41Z</dc:date>
    </item>
  </channel>
</rss>

