<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are some of the events garbled with &amp;quot;\x00&amp;quot;? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13336#M1219</link>
    <description>&lt;P&gt;Ideally, if you are having this symptom, you should be clear about the pattern of null characters (\x00).  Are they interleaved with the expected data?  Do they come in small bursts (ten bytes or so)?  Are there several kilobytes worth of nulls all at once?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jul 2010 03:20:25 GMT</pubDate>
    <dc:creator>jrodman</dc:creator>
    <dc:date>2010-07-15T03:20:25Z</dc:date>
    <item>
      <title>Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13333#M1216</link>
      <description>&lt;P&gt;I am indexing some logs and I see some events are filled with "\x00" while some other events are indexed correctly.  &lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2010 22:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13333#M1216</guid>
      <dc:creator>elusive</dc:creator>
      <dc:date>2010-05-12T22:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13334#M1217</link>
      <description>&lt;P&gt;Such behavior is observed when Unix Splunk instance is indexing mounted Windows logs.  Windows has a unique way of logging which Unix instance is not aware of causing to index with nulls "\x00". When indexing Windows logs such as iis, exchange, domain controller, and so on, install Splunk as a forwarder on the Windows box and have it forward to Unix Splunk indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2010 22:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13334#M1217</guid>
      <dc:creator>elusive</dc:creator>
      <dc:date>2010-05-12T22:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13335#M1218</link>
      <description>&lt;P&gt;This also happens sometimes when the data your indexing is encoded with a different character set such as UTF-16  &lt;/P&gt;

&lt;P&gt;You can specify the charset in your props.conf&lt;BR /&gt;
[somesourcetype]&lt;BR /&gt;
CHARSET = UTF-16  &lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2010 00:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13335#M1218</guid>
      <dc:creator>Chris_R_</dc:creator>
      <dc:date>2010-05-13T00:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13336#M1219</link>
      <description>&lt;P&gt;Ideally, if you are having this symptom, you should be clear about the pattern of null characters (\x00).  Are they interleaved with the expected data?  Do they come in small bursts (ten bytes or so)?  Are there several kilobytes worth of nulls all at once?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2010 03:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13336#M1219</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-07-15T03:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13337#M1220</link>
      <description>&lt;P&gt;I'm seeing an input from windows onto unix having \x00 and some other unknown characters interspersed with the data. Is UTF-16 the answer to this?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2010 22:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13337#M1220</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2010-07-23T22:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13338#M1221</link>
      <description>&lt;P&gt;Nope. UTF-16 turned a lot of the text into asian characters.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2010 01:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13338#M1221</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2010-07-24T01:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are some of the events garbled with "\x00"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13339#M1222</link>
      <description>&lt;P&gt;So, do we create props.conf on Forwarder TA or Indexer TA?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 16:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-some-of-the-events-garbled-with-quot-x00-quot/m-p/13339#M1222</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2016-08-09T16:44:52Z</dc:date>
    </item>
  </channel>
</rss>

