<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114192#M23862</link>
    <description>&lt;P&gt;I am looking at the data leaving the forwarder using wireshark.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2013 19:03:44 GMT</pubDate>
    <dc:creator>lewis15</dc:creator>
    <dc:date>2013-10-24T19:03:44Z</dc:date>
    <item>
      <title>why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114188#M23858</link>
      <description>&lt;P&gt;why is the data from splunk forwarder --splunk-cooked-mkode-v3-- then about 103 x00 then the computername fillowed by 241 x00 then 8089 followed by 12 more x00?&lt;/P&gt;

&lt;P&gt;I have tried to find something on the web that made sense to me to discover what the problem is.  I used Wireshark on the Windows 7 machine to trap the data.  The data looks the same on my Ubuntu 12.10 Splunk standalone indexer.&lt;BR /&gt;&lt;BR /&gt;
Thanks&lt;BR /&gt;
Lewis&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 16:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114188#M23858</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-24T16:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114189#M23859</link>
      <description>&lt;P&gt;Sounds like you've setup a TCP input (in the "Inputs" section in splunkweb) instead of a receiving port (In "Forwarding and receiving"). TCP inputs are read by Splunk as-is, while receiving ports are used for receiving data in the proprietary format that's used for forwarded data from one Splunk instance to another. Make sure you're sending forwarded data to a receiving port.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 18:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114189#M23859</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-24T18:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114190#M23860</link>
      <description>&lt;P&gt;universal forwarder does not use splunkweb.  There isn't an option in the windows setup to select TCP or UDP.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 18:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114190#M23860</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-24T18:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114191#M23861</link>
      <description>&lt;P&gt;No, I'm not talking about the forwarder, I'm talking about the Splunk instance you're sending data TO from the forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 18:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114191#M23861</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-24T18:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114192#M23862</link>
      <description>&lt;P&gt;I am looking at the data leaving the forwarder using wireshark.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114192#M23862</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-24T19:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114193#M23863</link>
      <description>&lt;P&gt;OK. What you are seeing is Splunk's own proprietary format for sending data. There's various metadata added apart from the actual raw event. This is not a problem, that's just how it's sent on the wire.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114193#M23863</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-24T19:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114194#M23864</link>
      <description>&lt;P&gt;So there isn't any event log data sent, just nulls - x00&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114194#M23864</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-24T19:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114195#M23865</link>
      <description>&lt;P&gt;Highly possible. You really should look for that in Splunk itself, not try to decipher it on the network layer.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114195#M23865</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-24T19:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114196#M23866</link>
      <description>&lt;P&gt;If the data that is in the network layer is going to be in the output layer.  Also I replaced the universal forwarder with a full Splunk version setup for forwarding and it does the same thing, just sends the computer name and lots of x00s.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 12:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114196#M23866</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-30T12:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114197#M23867</link>
      <description>&lt;P&gt;"I have tried to find something on the web that made sense to me to discover what the problem is." What exactly is the problem you are referencing/experiencing? 8090 is the management port the deployment server uses. Probably the client checking in with the deployment server. See step one.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Updating/Howdeploymentupdateshappen"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Updating/Howdeploymentupdateshappen&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 12:47:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114197#M23867</guid>
      <dc:creator>antlefebvre</dc:creator>
      <dc:date>2013-10-30T12:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114198#M23868</link>
      <description>&lt;P&gt;I don't know what else I can say to make you understand this. Data is sent in a proprietary format that will be more than just any log data sent. This is not a problem, this is just the way the data is sent.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 13:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114198#M23868</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-30T13:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114199#M23869</link>
      <description>&lt;P&gt;all null characters is not proprietary!!!!!!!!!!!!!!!!!!&lt;BR /&gt;
If there was data/information it would not be all 000000000000000000000000000s&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 15:43:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114199#M23869</guid>
      <dc:creator>lewis15</dc:creator>
      <dc:date>2013-10-30T15:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114200#M23870</link>
      <description>&lt;P&gt;Fine. So, what's the actual problem you're experiencing?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 15:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114200#M23870</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-10-30T15:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: why is splunkforwarder-6.0-182611-x64-release.msi sending mostly x00</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114201#M23871</link>
      <description>&lt;P&gt;lewis15. Please see answer I suggested. I believe you are seeing the deployment server poll packet.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2013 15:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/why-is-splunkforwarder-6-0-182611-x64-release-msi-sending-mostly/m-p/114201#M23871</guid>
      <dc:creator>antlefebvre</dc:creator>
      <dc:date>2013-10-30T15:54:33Z</dc:date>
    </item>
  </channel>
</rss>

