<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to decode 1945 bytes error:  Backup Exec logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93937#M97422</link>
    <description>&lt;P&gt;Found solution to my own problem.  I'm running Backup Exec 2010 and the logs are XML.  So....open a command prompt and:&lt;/P&gt;

&lt;P&gt;From :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;c:\Program Files\Symantec\Backup Exec run:

bemcmd -o31 -l"&amp;lt;output file name.txt&amp;gt;" -s0 -f"&amp;lt;job log.xml&amp;gt;"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is an example if you wanted to specify the location for the output file and or the job logs are located in another folder.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;bemcmd -o31 -l"BEX_TAPEBACKUP_00091.TXT" s0 -f"C:\Program Files\Symantec\Backup Exec\Data\BEX_TAPEBACKUP_00091.xml"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It will convert the xml to plain text and then you can index it in splunk.  It would be easy to schedule this as part of a batch script to convert it to txt.  &lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2013 21:02:48 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2013-04-15T21:02:48Z</dc:date>
    <item>
      <title>Failed to decode 1945 bytes error:  Backup Exec logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93935#M97420</link>
      <description>&lt;P&gt;I'm trying to preview a backup exec log in Splunk.  The log is in XML.  When I preview it in spulnk, I get the error:&lt;/P&gt;

&lt;P&gt;Failed to decode 1945 bytes; Failed to decode 2049 bytes&lt;/P&gt;

&lt;P&gt;Also the preview makes the entire file into gibberish.  It looks like this in splunk preview:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\xFF\xFE&amp;lt;\x00?\x00x\x00m\x00l\x00 \x00v\x00e\x00r\x00s\x00i\x00o\x00n\x00=\x00"\x001\x00.\x000\x00"\x00 \x00e\x00n\x00c\x00o\x00d\x00i\x00n\x00g\x00=\x00"\x00U\x00T\x00F\x00-\x001\x006\x00"\x00?\x00&amp;gt;\x00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;\x00&lt;BR /&gt;
\x00&amp;lt;\x00j\x00o\x00b\x00l\x00o\x00g\x00&amp;gt;\x00&amp;lt;\x00j\x00o\x00b\x00_\x00l\x00o\x00g\x00_\x00v\x00e\x00r\x00s\x00i\x00o\x00n\x00 \x00v\x00e\x00r\x00s\x00i\x00o\x00n\x00=\x00"\x002\x00.\x000\x00"\x00/\x00&amp;gt;\x00&amp;lt;\x00h\x00e\x00a\x00d\x00e\x00r\x00&amp;gt;\x00&amp;lt;\x00f\x00i\x00l\x00l\x00e\x00r\x00&amp;gt;\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00    \x00    \x00&amp;lt;\x00/\x00f\x00i\x00l\x00l\x00e\x00r\x00&amp;gt;\x00&amp;lt;\x00s\x00e\x00r\x00v\x00e\x00r\x00&amp;gt;\x00J\x00o\x00b\x00 \x00s\x00e\x00r\x00v\x00e\x00r\x00:\x00 \x00T\x00A\x00P\x00E\x00B\x00A\x00C\x00K\x00U\x00P\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00s\x00e\x00r\x00v\x00e\x00r\x00&amp;gt;\x00&amp;lt;\x00n\x00a\x00m\x00e\x00&amp;gt;\x00J\x00o\x00b\x00 \x00n\x00a\x00m\x00e\x00:\x00 \x00W\x00e\x00e\x00k\x00l\x00y\x00 \x00T\x00a\x00p\x00e\x00 \x00B\x00a\x00c\x00k\x00u\x00p\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00n\x00a\x00m\x00e\x00&amp;gt;\x00&amp;lt;\x00s\x00t\x00a\x00r\x00t\x00_\x00t\x00i\x00m\x00e\x00&amp;gt;\x00J\x00o\x00b\x00 \x00s\x00t\x00a\x00r\x00t\x00e\x00d\x00:\x00 \x00T\x00u\x00e\x00s\x00d\x00a\x00y\x00,\x00 \x00A\x00p\x00r\x00i\x00l\x00 \x000\x009\x00,\x00 \x002\x000\x001\x003\x00 \x00a\x00t\x00 \x005\x00:\x003\x000\x00:\x000\x001\x00 \x00A\x00M\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00s\x00t\x00a\x00r\x00t\x00_\x00t\x00i\x00m\x00e\x00&amp;gt;\x00&amp;lt;\x00t\x00y\x00p\x00e\x00&amp;gt;\x00J\x00o\x00b\x00 \x00t\x00y\x00p\x00e\x00:\x00 \x00B\x00a\x00c\x00k\x00u\x00p\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00t\x00y\x00p\x00e\x00&amp;gt;\x00&amp;lt;\x00l\x00o\x00g\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00J\x00o\x00b\x00 \x00L\x00o\x00g\x00:\x00 \x00B\x00E\x00X\x00_\x00T\x00A\x00P\x00E\x00B\x00A\x00C\x00K\x00U\x00P\x00_\x000\x000\x000\x008\x007\x00.\x00x\x00m\x00l\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00l\x00o\x00g\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00&amp;lt;\x00f\x00i\x00l\x00l\x00e\x00r\x00&amp;gt;\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00    \x00    \x00&amp;lt;\x00/\x00f\x00i\x00l\x00l\x00e\x00r\x00&amp;gt;\x00&amp;lt;\x00/\x00h\x00e\x00a\x00d\x00e\x00r\x00&amp;gt;\x00&amp;lt;\x00m\x00e\x00d\x00i\x00a\x00_\x00m\x00o\x00u\x00n\x00t\x00_\x00d\x00a\x00t\x00e\x00&amp;gt;\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00D\x00r\x00i\x00v\x00e\x00 \x00a\x00n\x00d\x00 \x00m\x00e\x00d\x00i\x00a\x00 \x00m\x00o\x00u\x00n\x00t\x00 \x00r\x00e\x00q\x00u\x00e\x00s\x00t\x00e\x00d\x00:\x00 \x004\x00/\x009\x00/\x002\x000\x001\x003\x00 \x005\x00:\x003\x000\x00:\x000\x001\x00 \x00A\x00M\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00m\x00e\x00d\x00i\x00a\x00_\x00m\x00o\x00u\x00n\x00t\x00_\x00d\x00a\x00t\x00e\x00&amp;gt;\x00&amp;lt;\x00m\x00e\x00d\x00i\x00a\x00_\x00d\x00r\x00i\x00v\x00e\x00_\x00a\x00n\x00d\x00_\x00m\x00e\x00d\x00i\x00a\x00_\x00i\x00n\x00f\x00o\x00&amp;gt;\x00&amp;lt;\x00m\x00e\x00d\x00i\x00a\x00_\x00m\x00o\x00u\x00n\x00t\x00_\x00d\x00a\x00t\x00e\x00&amp;gt;\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00D\x00r\x00i\x00v\x00e\x00 \x00a\x00n\x00d\x00 \x00m\x00e\x00d\x00i\x00a\x00 \x00i\x00n\x00f\x00o\x00r\x00m\x00a\x00t\x00i\x00o\x00n\x00 \x00f\x00r\x00o\x00m\x00 \x00m\x00e\x00d\x00i\x00a\x00 \x00m\x00o\x00u\x00n\x00t\x00:\x00 \x004\x00/\x009\x00/\x002\x000\x001\x003\x00 \x005\x00:\x003\x001\x00:\x002\x000\x00 \x00A\x00M\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00m\x00e\x00d\x00i\x00a\x00_\x00m\x00o\x00u\x00n\x00t\x00_\x00d\x00a\x00t\x00e\x00&amp;gt;\x00&amp;lt;\x00r\x00o\x00b\x00o\x00t\x00i\x00c\x00_\x00l\x00i\x00b\x00r\x00a\x00r\x00y\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00R\x00o\x00b\x00o\x00t\x00i\x00c\x00 \x00L\x00i\x00b\x00r\x00a\x00r\x00y\x00 \x00N\x00a\x00m\x00e\x00:\x00 \x00Q\x00U\x00A\x00N\x00T\x00U\x00M\x00 \x000\x000\x000\x002\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00r\x00o\x00b\x00o\x00t\x00i\x00c\x00_\x00l\x00i\x00b\x00r\x00a\x00r\x00y\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00&amp;lt;\x00d\x00r\x00i\x00v\x00e\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00D\x00r\x00i\x00v\x00e\x00 \x00N\x00a\x00m\x00e\x00:\x00 \x00Q\x00U\x00A\x00N\x00T\x00U\x00M\x00 \x000\x000\x000\x001\x00&lt;BR /&gt;
\x00&lt;BR /&gt;
\x00&amp;lt;\x00/\x00d\x00r\x00i\x00v\x00e\x00_\x00n\x00a\x00m\x00e\x00&amp;gt;\x00&amp;lt;\x00s\x00l\x00o\x00t\x00&amp;gt;\x00S\x00l\x00o\x00t\x00:\x00 \x002\x00&lt;BR /&gt;
\x00&lt;/P&gt;

&lt;P&gt;Anyone have this happening???????&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93935#M97420</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2020-09-28T13:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to decode 1945 bytes error:  Backup Exec logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93936#M97421</link>
      <description>&lt;P&gt;I'm wondering is it because the xml file is using &amp;lt;&amp;gt; symbols and splunk can't read those?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2013 14:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93936#M97421</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-04-15T14:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to decode 1945 bytes error:  Backup Exec logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93937#M97422</link>
      <description>&lt;P&gt;Found solution to my own problem.  I'm running Backup Exec 2010 and the logs are XML.  So....open a command prompt and:&lt;/P&gt;

&lt;P&gt;From :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;c:\Program Files\Symantec\Backup Exec run:

bemcmd -o31 -l"&amp;lt;output file name.txt&amp;gt;" -s0 -f"&amp;lt;job log.xml&amp;gt;"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is an example if you wanted to specify the location for the output file and or the job logs are located in another folder.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;bemcmd -o31 -l"BEX_TAPEBACKUP_00091.TXT" s0 -f"C:\Program Files\Symantec\Backup Exec\Data\BEX_TAPEBACKUP_00091.xml"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It will convert the xml to plain text and then you can index it in splunk.  It would be easy to schedule this as part of a batch script to convert it to txt.  &lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2013 21:02:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/93937#M97422</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-04-15T21:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to decode 1945 bytes error:  Backup Exec logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/530261#M97423</link>
      <description>&lt;P&gt;the solution which works for me is the&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;CHARSET &lt;/PRE&gt;&lt;P&gt;attribute in props try to set that to auto. it should work&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 19:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Failed-to-decode-1945-bytes-error-Backup-Exec-logs/m-p/530261#M97423</guid>
      <dc:creator>vinayakwagh</dc:creator>
      <dc:date>2020-11-20T19:59:35Z</dc:date>
    </item>
  </channel>
</rss>

