<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hidden control characters in logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81653#M97122</link>
    <description>&lt;P&gt;Not an answer on why Splunk isn't indexing your log, but you can check what ASCII value the character has by doing &lt;CODE&gt;cat old.log | hexdump -C&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2011 17:36:19 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-09-26T17:36:19Z</dc:date>
    <item>
      <title>Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81652#M97121</link>
      <description>&lt;P&gt;I have sinkhole directory which eats pretty much anything what goes in, but there are bunch of log files which are not indexed nor deleted.  &lt;/P&gt;

&lt;P&gt;With vim I can see some special characters: ^@ at the end of first two fields and ^Z at the end of file. With :set list option in addition there are displayed only $ (eol) which is perfectly fine.&lt;/P&gt;

&lt;P&gt;My question is what is this hidden character (^@) and can it prevent Splunk from indexing?&lt;/P&gt;

&lt;P&gt;I've tried cat old.log &amp;gt; new.log, but this does not eliminates those characters, they are not displayed with cat though (unless -v is specified).&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2011 15:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81652#M97121</guid>
      <dc:creator>giovere</dc:creator>
      <dc:date>2011-09-26T15:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81653#M97122</link>
      <description>&lt;P&gt;Not an answer on why Splunk isn't indexing your log, but you can check what ASCII value the character has by doing &lt;CODE&gt;cat old.log | hexdump -C&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2011 17:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81653#M97122</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-09-26T17:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81654#M97123</link>
      <description>&lt;P&gt;It sounds like you have a separate issue of the fact that logs are not being indexed.  Supplying your inputs.conf settings as well as a log sample would be helpful in debugging your problem.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2011 20:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81654#M97123</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2011-09-26T20:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81655#M97124</link>
      <description>&lt;P&gt;thanks for replies, I've tried hexdump -C could not notice anything suspicious.&lt;BR /&gt;
inputs.conf is really simple, just move policy set to sinkhole nothing else. I start to suspect maximum field length restriction. Here is only header, but it is sufficient to reproduce problem "not_indexed.txt" does not get indexed, but "indexed.txt" does. only difference is that indexed.txt has one less underscore character in the first field. &lt;A href="http://dl.dropbox.com/u/8430959/indexed.txt" target="_blank"&gt;http://dl.dropbox.com/u/8430959/indexed.txt&lt;/A&gt; &lt;A href="http://dl.dropbox.com/u/8430959/not_indexed.txt" target="_blank"&gt;http://dl.dropbox.com/u/8430959/not_indexed.txt&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81655#M97124</guid>
      <dc:creator>giovere</dc:creator>
      <dc:date>2020-09-28T09:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81656#M97125</link>
      <description>&lt;P&gt;What is the error in the splunkd.log that says why it wasn't indexed?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2011 07:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81656#M97125</guid>
      <dc:creator>bbingham</dc:creator>
      <dc:date>2011-10-01T07:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81657#M97126</link>
      <description>&lt;P&gt;09-27-2011 20:39:05.104 +0200 ERROR TailingProcessor - File will not be read, is too small to match seekptr checksum (file=/logrepo/not_indexed.txt).  Last time we saw this initcrc, filename was different.  You may wish to use a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81657#M97126</guid>
      <dc:creator>giovere</dc:creator>
      <dc:date>2020-09-28T09:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hidden control characters in logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81658#M97127</link>
      <description>&lt;P&gt;Found answer here: &lt;A href="http://splunk-base.splunk.com/answers/7457/error-tailingprocessor-unable-to-index-file"&gt;http://splunk-base.splunk.com/answers/7457/error-tailingprocessor-unable-to-index-file&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2011 13:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hidden-control-characters-in-logs/m-p/81658#M97127</guid>
      <dc:creator>giovere</dc:creator>
      <dc:date>2011-10-03T13:09:33Z</dc:date>
    </item>
  </channel>
</rss>

