<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log4j showing Hexadecimal in Preview in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84133#M97147</link>
    <description>&lt;P&gt;How are you receiving the data?  Via tcp/udp or reading a file directly?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2012 16:08:01 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2012-06-26T16:08:01Z</dc:date>
    <item>
      <title>log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84132#M97146</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I have a log file made through a log4j on a windows box. I open it through Kate&lt;/P&gt;

&lt;P&gt;06-12-12 20:20:32 THD=3304 INFO broker.operation - Reading key from the registry : 'XXXX'.&lt;BR /&gt;
06-12-12 20:20:32 THD=3304 INFO broker.operation - Error while reading the key value : The Starting instance time out is inactive.&lt;BR /&gt;
06-12-12 20:21:00 THD=3304 INFO system.net.http - Opening URL:&lt;/P&gt;

&lt;P&gt;and in Splunk I have this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;26/06/2012 14:46:15.000 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;\xFF\xFE0\x006\x00-\x001\x002\x00-\x001\x002\x00 \x002\x000\x00:\x002\x000\x00:\x003\x002\x00 \x00T\x00H\x00D\x00=\x003\x002\x008\x008\x00 \x00I\x00N\x00F\x00O\x00 \x00b\x00r\x00o\x00k\x00e\x00r\x00.\x00o\x00p\x00e\x00r\x00a\x00t\x00i\x00o\x00n\x00 \x00-\x00 \x00W\x00e\x00b\x00 \x00s\x00e\x00r\x00v\x00e\x00r\x00 \x00"\x00h\x00t\x00t\x00p\x00:\x00/\x00/\x00a\x00r\x00m\x00w\x00e\x00b\x00d\x00d\x00c\x000\x000\x001\x00/\x00m\x00a\x00g\x00n\x00i\x00t\x00u\x00d\x00e\x00_\x00p\x00r\x00o\x00d\x00"\x00 \x00c\x00o\x00n\x00t\x00a\x00c\x00t\x00e\x00d\x00 \x00a\x00b\x00o\x00u\x00t\x00 \x00s\x00e\x00r\x00v\x00e\x00r\x00 \x00s\x00t\x00a\x00r\x00t\x00 \x00o\x00n\x00 \x00c\x00o\x00m\x00p\x00u\x00t\x00e\x00r\x00 \x00A\x00R\x00M\x00B\x00O\x00C\x00D\x00D\x00C\x000\x001\x000\x00 \x00f\x00o\x00r\x00 \x00d\x00a\x00t\x00a\x00s\x00o\x00u\x00r\x00c\x00e\x00 \x00M\x00a\x00g\x00n\x00i\x00t\x00u\x00d\x00e\x00_\x00P\x00R\x00O\x00D\x00.\x00&lt;/P&gt;

&lt;P&gt;What could be the issue&lt;/P&gt;

&lt;P&gt;Thanks a lot&lt;BR /&gt;
Christophe&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84132#M97146</guid>
      <dc:creator>christopheh</dc:creator>
      <dc:date>2020-09-28T11:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84133#M97147</link>
      <description>&lt;P&gt;How are you receiving the data?  Via tcp/udp or reading a file directly?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2012 16:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84133#M97147</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-06-26T16:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84134#M97148</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I am reading from a file on my disks (transferred from the windows box)&lt;/P&gt;

&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2012 16:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84134#M97148</guid>
      <dc:creator>christopheh</dc:creator>
      <dc:date>2012-06-26T16:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84135#M97149</link>
      <description>&lt;P&gt;Hmm, I'm lost on why that would occur.  I've only seen hex data when I had tried sending tcp syslog data to a splunktcp listener.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2012 16:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84135#M97149</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-06-26T16:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84136#M97150</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have analysed the file and it appears to be in Little-endian UTF-16 Unicode English text, with CRLF line terminators&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2012 07:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84136#M97150</guid>
      <dc:creator>christopheh</dc:creator>
      <dc:date>2012-06-27T07:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: log4j showing Hexadecimal in Preview</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84137#M97151</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;in the meantime i use this to convert from utf16 to utf8&lt;BR /&gt;
 iconv -f UTF-16 -t UTF-8 -o dest.log source.log&lt;/P&gt;

&lt;P&gt;and now it works like a charm&lt;/P&gt;

&lt;P&gt;Thanks mikeanghorst&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2012 07:51:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/log4j-showing-Hexadecimal-in-Preview/m-p/84137#M97151</guid>
      <dc:creator>christopheh</dc:creator>
      <dc:date>2012-06-27T07:51:00Z</dc:date>
    </item>
  </channel>
</rss>

