<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk parsing issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing-issue/m-p/78885#M16151</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I'm new to the splunk technology, so there have been a few things that I'm stuck with. I have a log format with a field that includes a binary number, so either a single 0 or 1 digit. I'm trying to extract a new field to name this field accordingly, but splunk is having a hard time parsing and identifying this field correctly. I provide a few examples but it only recognizes the zeros in the date field... anyone know what I could do to get it to identify this specific field? Thank you!!&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jun 2012 21:35:23 GMT</pubDate>
    <dc:creator>monicato</dc:creator>
    <dc:date>2012-06-19T21:35:23Z</dc:date>
    <item>
      <title>Splunk parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing-issue/m-p/78885#M16151</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I'm new to the splunk technology, so there have been a few things that I'm stuck with. I have a log format with a field that includes a binary number, so either a single 0 or 1 digit. I'm trying to extract a new field to name this field accordingly, but splunk is having a hard time parsing and identifying this field correctly. I provide a few examples but it only recognizes the zeros in the date field... anyone know what I could do to get it to identify this specific field? Thank you!!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 21:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing-issue/m-p/78885#M16151</guid>
      <dc:creator>monicato</dc:creator>
      <dc:date>2012-06-19T21:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing-issue/m-p/78886#M16152</link>
      <description>&lt;P&gt;Is it possible to convert those binary bits to ascii before Splunk indexes it?  If so, that would be the route I would go.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 02:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-parsing-issue/m-p/78886#M16152</guid>
      <dc:creator>Lamar</dc:creator>
      <dc:date>2012-06-20T02:39:39Z</dc:date>
    </item>
  </channel>
</rss>

