<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic encoded data over tcp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/encoded-data-over-tcp/m-p/81060#M16718</link>
    <description>&lt;P&gt;Hi I am able to send log4j log data to splunk over tcp network but the data in splunk is not human readable.(see below) This is totally different than the original log data. Can anyone shed some light on this? Thanks! &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;log4j.properties&lt;/STRONG&gt;&lt;BR /&gt;
    log4j.rootCategory=INFO, socket&lt;BR /&gt;
    log4j.appender.socket=org.apache.log4j.net.SocketAppender&lt;BR /&gt;
    log4j.appender.socket.port=33333&lt;BR /&gt;
    log4j.appender.socket.remoteHost=myLinuxServer1&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;tcp:33333&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\xAC\xED\x00\x5sr\x00!org.apache.log4j.spi.LoggingEvent\xF3\xF2\xB9#t\xB\xB5?\x3\x00
Z\x00\x15mdcCopyLookupRequiredZ\x00\x11ndcLookupRequiredJ\x00   timeStampL\x00\xCcategoryNamet\x00\x12Ljava/lang/String;L\x00\xClocationInfot\x00#Lorg/apache/log4j/spi/LocationInfo;L\x00\x7mdcCopyt\x00\x15Ljava/util/Hashtable;L\x00\x3ndcq\x00~\x00\x1L\x00\xFrenderedMessageq\x00~\x00\x1L\x00
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 21 Jun 2012 16:39:46 GMT</pubDate>
    <dc:creator>shangshin</dc:creator>
    <dc:date>2012-06-21T16:39:46Z</dc:date>
    <item>
      <title>encoded data over tcp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/encoded-data-over-tcp/m-p/81060#M16718</link>
      <description>&lt;P&gt;Hi I am able to send log4j log data to splunk over tcp network but the data in splunk is not human readable.(see below) This is totally different than the original log data. Can anyone shed some light on this? Thanks! &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;log4j.properties&lt;/STRONG&gt;&lt;BR /&gt;
    log4j.rootCategory=INFO, socket&lt;BR /&gt;
    log4j.appender.socket=org.apache.log4j.net.SocketAppender&lt;BR /&gt;
    log4j.appender.socket.port=33333&lt;BR /&gt;
    log4j.appender.socket.remoteHost=myLinuxServer1&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;tcp:33333&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\xAC\xED\x00\x5sr\x00!org.apache.log4j.spi.LoggingEvent\xF3\xF2\xB9#t\xB\xB5?\x3\x00
Z\x00\x15mdcCopyLookupRequiredZ\x00\x11ndcLookupRequiredJ\x00   timeStampL\x00\xCcategoryNamet\x00\x12Ljava/lang/String;L\x00\xClocationInfot\x00#Lorg/apache/log4j/spi/LocationInfo;L\x00\x7mdcCopyt\x00\x15Ljava/util/Hashtable;L\x00\x3ndcq\x00~\x00\x1L\x00\xFrenderedMessageq\x00~\x00\x1L\x00
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Jun 2012 16:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/encoded-data-over-tcp/m-p/81060#M16718</guid>
      <dc:creator>shangshin</dc:creator>
      <dc:date>2012-06-21T16:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: encoded data over tcp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/encoded-data-over-tcp/m-p/81061#M16719</link>
      <description>&lt;P&gt;I can only guess that the character encoding is not UTF-8. See &lt;A href="http://answers.splunk.com/answers/129428/character-encoding-when-sending-to-tcp-port"&gt;this answer&lt;/A&gt; for more information.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 12:17:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/encoded-data-over-tcp/m-p/81061#M16719</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2014-03-31T12:17:11Z</dc:date>
    </item>
  </channel>
</rss>

