<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do i convert/fix my cooked data to human readable data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253384#M96108</link>
    <description>&lt;P&gt;I've installed a universal forwarder(A) on a linux box which monitors a .log file and forwards data to an intermediate forwarder(B) on port 10200. The intermediate forwarder listens on the port ( it also has 'index=test02' and 'sourcetype=test02' entries ) and sends the data to an indexer_cluster. From my search head, when I search for index=test02 I receive the below data snipit. &lt;/P&gt;

&lt;P&gt;Universal Forwarder(A) 6.5.1 and Universal Forwarder(B) 6.4.3&lt;BR /&gt;
Splunk Cluster v6.5.0(in the middle of upgrading to 6.5.1)&lt;/P&gt;

&lt;P&gt;I've tried a few things: &lt;BR /&gt;
modified the outputs.conf [tcpout] compressed=false ... on the universal forwarder (A) &lt;BR /&gt;
modified the inputs.conf on the intermediate forwarder to listen on [splunktcp://:10200]&lt;BR /&gt;
modified the inputs.conf on the intermediate forwarder removing the index=test02 and sourcetype=test02 entries&lt;BR /&gt;
the indexers have port 9997 enabled within settings -&amp;gt; forwarding&amp;amp;receiving-&amp;gt;receiving&lt;BR /&gt;
I've reviewed the /var/log/splunkd.log and metrics.log on both (A) and (B) forwarders.&lt;BR /&gt;
I've reviewed index=_internal on the indexers within the cluster&lt;BR /&gt;
I've reviewed many links but maybe i missed something&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;My request for help:&lt;/STRONG&gt; Why is this happening and how do I get the data to human readable when I search for index=test02 on the search head&lt;BR /&gt;
** Additional question:** I am not using port 9997 for the universal forwarders, does this pose a problem in my scenario/setup?&lt;/P&gt;

&lt;P&gt;Thank You!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;--splunk-cooked-mode-v3----splunk-cooked-mode-v3--0\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00test01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x008089\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00&amp;#1;\x00\x00\x00&amp;#19;__s2s_capabilities\x00\x00\x00\x00&amp;#20;ack=0;compression=0\x00\x00\x00\x00\x00\x00\x00\x00&amp;#5;_raw\x00x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x008089\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00&amp;#1;\x00\x00\x00&amp;#19;__s2s_capabilities\x00\x00\x00\x00&amp;#20;ack=0;compression=0\x00\x00\x00\x00\x00\x00\x00\x00&amp;#5;_raw\x00
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 25 Jan 2017 17:22:08 GMT</pubDate>
    <dc:creator>rewritex</dc:creator>
    <dc:date>2017-01-25T17:22:08Z</dc:date>
    <item>
      <title>How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253384#M96108</link>
      <description>&lt;P&gt;I've installed a universal forwarder(A) on a linux box which monitors a .log file and forwards data to an intermediate forwarder(B) on port 10200. The intermediate forwarder listens on the port ( it also has 'index=test02' and 'sourcetype=test02' entries ) and sends the data to an indexer_cluster. From my search head, when I search for index=test02 I receive the below data snipit. &lt;/P&gt;

&lt;P&gt;Universal Forwarder(A) 6.5.1 and Universal Forwarder(B) 6.4.3&lt;BR /&gt;
Splunk Cluster v6.5.0(in the middle of upgrading to 6.5.1)&lt;/P&gt;

&lt;P&gt;I've tried a few things: &lt;BR /&gt;
modified the outputs.conf [tcpout] compressed=false ... on the universal forwarder (A) &lt;BR /&gt;
modified the inputs.conf on the intermediate forwarder to listen on [splunktcp://:10200]&lt;BR /&gt;
modified the inputs.conf on the intermediate forwarder removing the index=test02 and sourcetype=test02 entries&lt;BR /&gt;
the indexers have port 9997 enabled within settings -&amp;gt; forwarding&amp;amp;receiving-&amp;gt;receiving&lt;BR /&gt;
I've reviewed the /var/log/splunkd.log and metrics.log on both (A) and (B) forwarders.&lt;BR /&gt;
I've reviewed index=_internal on the indexers within the cluster&lt;BR /&gt;
I've reviewed many links but maybe i missed something&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;My request for help:&lt;/STRONG&gt; Why is this happening and how do I get the data to human readable when I search for index=test02 on the search head&lt;BR /&gt;
** Additional question:** I am not using port 9997 for the universal forwarders, does this pose a problem in my scenario/setup?&lt;/P&gt;

&lt;P&gt;Thank You!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;--splunk-cooked-mode-v3----splunk-cooked-mode-v3--0\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00test01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x008089\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00&amp;#1;\x00\x00\x00&amp;#19;__s2s_capabilities\x00\x00\x00\x00&amp;#20;ack=0;compression=0\x00\x00\x00\x00\x00\x00\x00\x00&amp;#5;_raw\x00x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x008089\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00&amp;#1;\x00\x00\x00&amp;#19;__s2s_capabilities\x00\x00\x00\x00&amp;#20;ack=0;compression=0\x00\x00\x00\x00\x00\x00\x00\x00&amp;#5;_raw\x00
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253384#M96108</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2017-01-25T17:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253385#M96109</link>
      <description>&lt;P&gt;Have a look at this post.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/13196/universal-forwarder-sending-cooked-data-to-indexer.html"&gt;https://answers.splunk.com/answers/13196/universal-forwarder-sending-cooked-data-to-indexer.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253385#M96109</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-01-25T17:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253386#M96110</link>
      <description>&lt;P&gt;@rewritex - It's not very clear what you need help with. Please provide more information so that other users can attempt to help. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253386#M96110</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-01-25T17:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253387#M96111</link>
      <description>&lt;P&gt;Thank You. Yes, I've read this post before. &lt;BR /&gt;
I've tried compensating for cooked data by using [splunktcp://:&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253387#M96111</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2017-01-25T17:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253388#M96112</link>
      <description>&lt;P&gt;Thank You aaraneta - I've updated my original post to hopefully be more clear and provide additional information&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 18:01:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253388#M96112</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2017-01-25T18:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do i convert/fix my cooked data to human readable data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253389#M96113</link>
      <description>&lt;P&gt;I've just figured it out .. It basically boils down to the Splunk2Splunk data using the [splunktcp://:9997] entry within the inputs.conf.&lt;/P&gt;

&lt;P&gt;Universal Forwarder (B) - Intermediate forwarder - inputs.conf&lt;BR /&gt;
I modified the inputs.conf to listen on [splunktcp://:9997] and didn't have any additional parameters.&lt;/P&gt;

&lt;P&gt;Universal Forwarder (A) - &lt;BR /&gt;
Outputs.conf - I setup the outputs to talk with the server using port 9997&lt;BR /&gt;
Inputs.conf - Using the cli command used the inputs.conf in the search app ($SPLUNK_HOME/etc/apps/search/local) where I added the index=test02 entry so the data goes into its own index. Without this the data was going into index=main.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/logging/logs/test02_server.log]
disabled = false
index=test-02
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now the Linux group is working, I will work on the windows servers and update this question after i'm done. Its always funny as soon as I post here, I figure out the answer ... or someone provides insite that helps me get to a solution. Thank you. &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 21:33:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-convert-fix-my-cooked-data-to-human-readable-data/m-p/253389#M96113</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2017-01-25T21:33:43Z</dc:date>
    </item>
  </channel>
</rss>

