<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoing remote file server log have \x00\ in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441895#M95810</link>
    <description>&lt;P&gt;Right. If you look at the url I posted you can see the solution - &lt;/P&gt;

&lt;P&gt;Automatically at parsing ("indexing") time for any new data, in &lt;CODE&gt;props.conf&lt;/CODE&gt; -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    [yoursourcetype]
    SEDCMD-remove_nulls = s/\\x00//g
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 20 Dec 2018 16:56:51 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2018-12-20T16:56:51Z</dc:date>
    <item>
      <title>Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441888#M95803</link>
      <description>&lt;P&gt;Usually first few line have issue, I suspect the Application still writing the log to the log file but splunk try to read the log file&lt;/P&gt;

&lt;P&gt;Can we setup splunk to wait ?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 01:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441888#M95803</guid>
      <dc:creator>kennethyeung</dc:creator>
      <dc:date>2018-12-20T01:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441889#M95804</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Can you give more details about your problem. An example probably.&lt;/P&gt;

&lt;P&gt;Sid&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 06:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441889#M95804</guid>
      <dc:creator>sdchakraborty</dc:creator>
      <dc:date>2018-12-20T06:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441890#M95805</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;you can not (easily) delay ingestion of data, but see this post for help:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/705953/can-you-delay-a-universal-forwarder-from-ingesting.html#answer-708749"&gt;https://answers.splunk.com/answers/705953/can-you-delay-a-universal-forwarder-from-ingesting.html#answer-708749&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 06:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441890#M95805</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-20T06:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441891#M95806</link>
      <description>&lt;P&gt;example, in the index, i will see below event&lt;BR /&gt;
1 . \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\ ................................................&lt;BR /&gt;
2 .#Software: Microsoft Exchange Server&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441891#M95806</guid>
      <dc:creator>kennethyeung</dc:creator>
      <dc:date>2018-12-20T08:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441892#M95807</link>
      <description>&lt;P&gt;Thanks, my splunk is Windows Server, and the log file we didnt install the agent to forward the log.&lt;/P&gt;

&lt;P&gt;we just monitor it by file share &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:16:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441892#M95807</guid>
      <dc:creator>kennethyeung</dc:creator>
      <dc:date>2018-12-20T08:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441893#M95808</link>
      <description>&lt;P&gt;Doesn´t matter if forwarder or fileshare monitor.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 08:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441893#M95808</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-20T08:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441894#M95809</link>
      <description>&lt;P&gt;The following worked for me a couple of times - &lt;A href="https://answers.splunk.com/answers/83790/how-do-i-remove-x00-characters-from-my-log-message.html"&gt;How do I remove \x00 characters from my log message?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441894#M95809</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-12-20T14:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoing remote file server log have \x00\</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441895#M95810</link>
      <description>&lt;P&gt;Right. If you look at the url I posted you can see the solution - &lt;/P&gt;

&lt;P&gt;Automatically at parsing ("indexing") time for any new data, in &lt;CODE&gt;props.conf&lt;/CODE&gt; -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    [yoursourcetype]
    SEDCMD-remove_nulls = s/\\x00//g
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Dec 2018 16:56:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoing-remote-file-server-log-have-x00/m-p/441895#M95810</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-12-20T16:56:51Z</dc:date>
    </item>
  </channel>
</rss>

