<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue :- Searching hexadecimal Data from Windows host in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467236#M131497</link>
    <description>&lt;P&gt;No Difference in search results but warning is not there in splunkd.log&lt;BR /&gt;
If i am creating props.conf at UF also, it is stopping data ingestion also.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Oct 2019 14:06:26 GMT</pubDate>
    <dc:creator>dvohra</dc:creator>
    <dc:date>2019-10-29T14:06:26Z</dc:date>
    <item>
      <title>Issue :- Searching hexadecimal Data from Windows host</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467234#M131495</link>
      <description>&lt;P&gt;I have recently deployed Splunk UF on windows machined, installation and setup is successful. But while searching the logs I am getting Hexadecimal data as below&lt;/P&gt;

&lt;P&gt;1\x000\x00-\x002\x009\x00-\x001\x009\x00 \x001\x000\x00:\x004\x000\x00:\x001\x009\x00 \x00P\x00I\x00D\x00=\x005\x007\x007\x006\x00 \x00T\x00H\x00D\x00=\x005\x004\x005\x002\x00 \x00U\x00S\x00R\x00=\x00 \x00M\x00S\x00G\x00=\x000\x00 \x00I\x00N\x00F\x00O\x00 \x00a\x00p\x00p\x00l\x00i\x00c\x00a\x00t\x00i\x00o\x00n\x00 \x00-&lt;/P&gt;

&lt;P&gt;As per Splunk answers i updated the props.conf on indexer as below. But it didn`t resolve the issue.&lt;/P&gt;

&lt;P&gt;[sourcetype]&lt;BR /&gt;
CHARSET = UTF-16LE&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;/P&gt;

&lt;P&gt;Can someone please assist here.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467234#M131495</guid>
      <dc:creator>dvohra</dc:creator>
      <dc:date>2020-09-30T02:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issue :- Searching hexadecimal Data from Windows host</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467235#M131496</link>
      <description>&lt;P&gt;Hi dvohra,&lt;BR /&gt;
are you sure that the charset you used is correct?&lt;BR /&gt;
What do you receive using "CHARSET = auto"?&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 13:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467235#M131496</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-29T13:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue :- Searching hexadecimal Data from Windows host</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467236#M131497</link>
      <description>&lt;P&gt;No Difference in search results but warning is not there in splunkd.log&lt;BR /&gt;
If i am creating props.conf at UF also, it is stopping data ingestion also.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 14:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467236#M131497</guid>
      <dc:creator>dvohra</dc:creator>
      <dc:date>2019-10-29T14:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issue :- Searching hexadecimal Data from Windows host</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467237#M131498</link>
      <description>&lt;P&gt;Hi dvohra,&lt;BR /&gt;
props.conf must be located on Indexers or (when present) on Heavy Forwarders, not on Universal Forwarders, with the inly exception of csv and xml.&lt;BR /&gt;
Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 14:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467237#M131498</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-29T14:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue :- Searching hexadecimal Data from Windows host</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467238#M131499</link>
      <description>&lt;P&gt;What does your inputs.conf look like on the UF? Is this about the windows event logs, or some other data you're trying to ingest?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 18:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issue-Searching-hexadecimal-Data-from-Windows-host/m-p/467238#M131499</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-10-29T18:27:32Z</dc:date>
    </item>
  </channel>
</rss>

