<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sharepoint logs are coming in Hex in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98130#M97508</link>
    <description>&lt;P&gt;Did you try changing the encoding? see: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Configurecharactersetencoding"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Nov 2014 23:40:14 GMT</pubDate>
    <dc:creator>jmeyers_splunk</dc:creator>
    <dc:date>2014-11-04T23:40:14Z</dc:date>
    <item>
      <title>Sharepoint logs are coming in Hex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98128#M97506</link>
      <description>&lt;P&gt;Attempting to Splunk Sharepoint 2010 logs but it's unreadable in the UI&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;0\x004\x00/\x001\x007\x00/\x002\x000\x001...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Using the file command on linux, it says the file is UTF-16 Little Endian.  Trying to set that charset on the sourcetype doesn't have any effect.  In fact seems to conflict in the server, as I get messages that monitor detects UTF-8.  Looking at a very old wiki page, mentions&lt;BR /&gt;
    splunk cmd classify &lt;FILENAME&gt;&lt;/FILENAME&gt;&lt;/P&gt;

&lt;P&gt;But that classifier is wrong, saying it is UTF-8 binary.&lt;/P&gt;

&lt;P&gt;Output of classify:&lt;BR /&gt;
    WARN  FileClassifierManager - The file 'FSHPTP02-20130408-1404.log' is invalid. Reason: binary&lt;BR /&gt;
    PROPERTIES OF FSHPTP02-20130408-1404.log&lt;BR /&gt;
    PropertiesMap: {&lt;BR /&gt;
        CHARSET -&amp;gt; UTF-8&lt;BR /&gt;
        invalid_cause -&amp;gt; binary&lt;BR /&gt;
        is_valid -&amp;gt; False&lt;BR /&gt;
        sourcetype -&amp;gt; unknown&lt;BR /&gt;
    }&lt;/P&gt;

&lt;P&gt;But the linux file command says otherwise:&lt;BR /&gt;
    [mlanghor@mlanghor-wkstn U]$ file FSHPTP02-20130408-1404.log&lt;BR /&gt;
FSHPTP02-20130408-1404.log: Little-endian UTF-16 Unicode English text, with very long lines, with CRLF line terminators&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98128#M97506</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T13:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sharepoint logs are coming in Hex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98129#M97507</link>
      <description>&lt;P&gt;Any resolution on this I have the same issue.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2013 17:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98129#M97507</guid>
      <dc:creator>hvandenb</dc:creator>
      <dc:date>2013-05-23T17:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sharepoint logs are coming in Hex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98130#M97508</link>
      <description>&lt;P&gt;Did you try changing the encoding? see: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Configurecharactersetencoding"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Nov 2014 23:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98130#M97508</guid>
      <dc:creator>jmeyers_splunk</dc:creator>
      <dc:date>2014-11-04T23:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Sharepoint logs are coming in Hex</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98131#M97509</link>
      <description>&lt;P&gt;See &lt;A href="http://wiki.splunk.com/Community:WindowsCharacterEncoding"&gt;http://wiki.splunk.com/Community:WindowsCharacterEncoding&lt;/A&gt;, which provides a solution for&lt;BR /&gt;
 - Logs coming in as hex&lt;BR /&gt;
 - Logs not monitored with the messages: "TailReader - Ignoring file '' due to: binary" and "FileClassifierManager - The file '' is invalid. Reason: binary"&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 10:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sharepoint-logs-are-coming-in-Hex/m-p/98131#M97509</guid>
      <dc:creator>mcs24</dc:creator>
      <dc:date>2016-02-11T10:03:14Z</dc:date>
    </item>
  </channel>
</rss>

