<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I seeing strange characters for Windows event log fields? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225168#M44044</link>
    <description>&lt;P&gt;Thank you, not sure it does the trick since I pretty much gave up on Splunk and went with Graylog.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2016 18:49:19 GMT</pubDate>
    <dc:creator>CypherBit</dc:creator>
    <dc:date>2016-06-15T18:49:19Z</dc:date>
    <item>
      <title>Why am I seeing strange characters for Windows event log fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225165#M44041</link>
      <description>&lt;P&gt;I'm using Windows Event Forwarding to gather all the needed events on our collector running 2012 R2. Splunk 6.4.0 is installed on this same server.&lt;/P&gt;

&lt;P&gt;I've added the data, Monitor\Local Event Logs\ForwardedEvents. All the events are present, but I'm having the following issues:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Type is displayed as: Type=윐ᇣp&lt;/LI&gt;
&lt;LI&gt;Message is displayed as: Message=윐ᇣp&lt;/LI&gt;
&lt;LI&gt;Same for OpCode=윐ᇣp&lt;/LI&gt;
&lt;LI&gt;Additionaly: User=NOT_TRANSLATED&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I'm very new to Splunk, so try to be as verbose as possible what needs changing and where. I tried using RenderXML = 1, but I still don't see the text, which is displayed correctly when viewed with Event Viewer.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 20:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225165#M44041</guid>
      <dc:creator>CypherBit</dc:creator>
      <dc:date>2016-04-27T20:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing strange characters for Windows event log fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225166#M44042</link>
      <description>&lt;P&gt;I had exactly the same issue. To resolve, change the content format of your subscription from Rendered Text to Events:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;wecutil ss "subscription name" /cf:Events
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 May 2016 12:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225166#M44042</guid>
      <dc:creator>abpe</dc:creator>
      <dc:date>2016-05-13T12:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing strange characters for Windows event log fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225167#M44043</link>
      <description>&lt;P&gt;I had the same issue, this solution fixed my problem.&lt;BR /&gt;
Thanks for the tip.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 09:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225167#M44043</guid>
      <dc:creator>bgaignon</dc:creator>
      <dc:date>2016-06-15T09:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing strange characters for Windows event log fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225168#M44044</link>
      <description>&lt;P&gt;Thank you, not sure it does the trick since I pretty much gave up on Splunk and went with Graylog.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 18:49:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-strange-characters-for-Windows-event-log-fields/m-p/225168#M44044</guid>
      <dc:creator>CypherBit</dc:creator>
      <dc:date>2016-06-15T18:49:19Z</dc:date>
    </item>
  </channel>
</rss>

