<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SplunkForwarder garble events with \x00 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84808#M17628</link>
    <description>&lt;P&gt;I observe a strange behavior with one of out UniversalForwarders.&lt;/P&gt;

&lt;P&gt;First I've added a new logfile on the forwarder with CLI. Events looks good on a search.&lt;/P&gt;

&lt;P&gt;After that I'vre removed the monitor and re-added with "-sourcetype cerberus-ftp".&lt;/P&gt;

&lt;P&gt;Result: Events are not encoded anymore:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\x00[\x002\x000\x001\x003\x00-\x000\x007\x00-\x000\x004\x00 \x001\x004\x00:\x002\x005\x00:\x003\x003\x00]\x00:\x00C\x00O\x00N\x00N\x00E\x00C\x00T\x00 \x00[\x00 \x00 \x001\x003\x007\x000\x00]\x00 \x00-\x00 \x00T\x00h\x00e\x00 \x00c\x00l\x00i\x00e\x00n\x00t\x00 \x00c\x00l\x00o\x00s\x00e\x00d\x00 \x00t\x00h\x00e\x00 \x00c\x00o\x00n\x00n\x00e\x00c\x00t\x00i\x00o\x00n\x00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've tried to add "CHARSET = UTF-16" to props.conf. Nothing changed.&lt;/P&gt;

&lt;P&gt;If I remove the monitor and add without the sourcetype specified the event is displayed correctly.&lt;/P&gt;

&lt;P&gt;Our Setup:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Windows SplunkForwarder 5.0.2&lt;/LI&gt;
&lt;LI&gt;Linux Indexer 5.0.1 &lt;/LI&gt;
&lt;LI&gt;Linux SearchHead 5.0.1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Some ideas how to fix the encoding and why the specification of the sourcetype change it?&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2013 12:40:07 GMT</pubDate>
    <dc:creator>berndg</dc:creator>
    <dc:date>2013-07-04T12:40:07Z</dc:date>
    <item>
      <title>SplunkForwarder garble events with \x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84808#M17628</link>
      <description>&lt;P&gt;I observe a strange behavior with one of out UniversalForwarders.&lt;/P&gt;

&lt;P&gt;First I've added a new logfile on the forwarder with CLI. Events looks good on a search.&lt;/P&gt;

&lt;P&gt;After that I'vre removed the monitor and re-added with "-sourcetype cerberus-ftp".&lt;/P&gt;

&lt;P&gt;Result: Events are not encoded anymore:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\x00[\x002\x000\x001\x003\x00-\x000\x007\x00-\x000\x004\x00 \x001\x004\x00:\x002\x005\x00:\x003\x003\x00]\x00:\x00C\x00O\x00N\x00N\x00E\x00C\x00T\x00 \x00[\x00 \x00 \x001\x003\x007\x000\x00]\x00 \x00-\x00 \x00T\x00h\x00e\x00 \x00c\x00l\x00i\x00e\x00n\x00t\x00 \x00c\x00l\x00o\x00s\x00e\x00d\x00 \x00t\x00h\x00e\x00 \x00c\x00o\x00n\x00n\x00e\x00c\x00t\x00i\x00o\x00n\x00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've tried to add "CHARSET = UTF-16" to props.conf. Nothing changed.&lt;/P&gt;

&lt;P&gt;If I remove the monitor and add without the sourcetype specified the event is displayed correctly.&lt;/P&gt;

&lt;P&gt;Our Setup:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Windows SplunkForwarder 5.0.2&lt;/LI&gt;
&lt;LI&gt;Linux Indexer 5.0.1 &lt;/LI&gt;
&lt;LI&gt;Linux SearchHead 5.0.1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Some ideas how to fix the encoding and why the specification of the sourcetype change it?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2013 12:40:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84808#M17628</guid>
      <dc:creator>berndg</dc:creator>
      <dc:date>2013-07-04T12:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder garble events with \x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84809#M17629</link>
      <description>&lt;P&gt;Can you please share your input and props conf files ?
I have the same issue  with the same architecture and i cannot solve it&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2013 10:12:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84809#M17629</guid>
      <dc:creator>jonthanze</dc:creator>
      <dc:date>2013-10-02T10:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder garble events with \x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84810#M17630</link>
      <description>&lt;P&gt;I had the exact same issue.  No matter what I changed the sourcetype to, unless it was "server", which is the default, I got those characters coming through.&lt;/P&gt;

&lt;P&gt;I even tried the charset suggestion from here &lt;A href="http://answers.splunk.com/answers/24484/sql-server-errorlog"&gt;http://answers.splunk.com/answers/24484/sql-server-errorlog&lt;/A&gt;, but then on one server I started to get even stranger results.&lt;/P&gt;

&lt;P&gt;Only seems to happen with the Cerberus FTP log file though.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 20:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84810#M17630</guid>
      <dc:creator>russellliss</dc:creator>
      <dc:date>2014-01-22T20:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: SplunkForwarder garble events with \x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84811#M17631</link>
      <description>&lt;P&gt;Did you ever get a solution to this? Also, I assume this is for logs for cerberus ftp? If so could you please provide your solution for getting the logs from cerberus?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 15:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunkForwarder-garble-events-with-x00/m-p/84811#M17631</guid>
      <dc:creator>josh_beverly</dc:creator>
      <dc:date>2018-09-19T15:53:49Z</dc:date>
    </item>
  </channel>
</rss>

