Getting Data In

After importing a CSV file in Splunk Light, why is event data displaying in the format "\x002\x00/\x001\x003\..."?

belljar1
New Member

Hey,

I am a total Splunk Noob. I am trying out Splunk Light. I can successfully import a file, but I cannot get splunk to display the data correctly.

This is an example of how an event looks in splunk once imported from the CSV:

\x002\x00/\x001\x003\x00/\x002\x000\x001\x005\x00 \x001\x002\x00:\x000\x003\x00 \x00A\x00M\x00,\x00I\x00n\x00f\x00o\x00,\x001\x000\x00.\x001\x004\x000\x00.\x009\x000\x00.\x001\x000\x001\x00,\x00"\x00<\x00<\x001\x004\x002\x003\x008\x001\x001\x000\x004\x006\x009\x006\x006\x00>\x00>\x00"\x00,\x00"\x00C\x00C\x00"\x00,\x00"\x000\x000\x000\x00"\x00,\x00"\x00V\x001\x001\x000\x00"\x00,\x00"\x000\x002\x00"\x00,\x00"\x004\x002\x00 \x004\x009\x00 \x004\x00E\x00 \x005\x004\x00 \x005\x002\x00 \x004\x006\x00 \x004\x003\x00 \x004\x005\x00 \x006\x005\x00 \x007\x002\x00 \x007\x002\x00 \x006\x00E\x00 \x006\x00F\x00 \x003\x00D\x00 \x003\x006\x00 \x003\x000\x00 \x000\x000\x00 \x000\x000\x00 \x00(\x00B\x00I\x00N\x00T\x00R\x00F\x00C\x00E\x00e\x00r\x00r\x00n\x00o\x00.\x006\x000\x00.\x00.\x00)\x00"\x00,\x00"\x001\x005\x000\x002\x001\x002\x00"\x00,\x00"\x002\x003\x004\x007\x004\x000\x00"\x00 \x00{\x00o\x006\x00m\x00k\x00D\x00L\x00a\x00w\x00P\x00b\x00o\x00o\x005\x00B\x00D\x00w\x00b\x00W\x00X\x00/\x00G\x00T\x00M\x00s\x00j\x00y\x00w\x008\x00y\x00k\x00M\x00g\x00F\x00L\x00Q\x00f\x00e\x00m\x00z\x009\x00r\x006\x00o\x00=\x00}\x00

The source is a UTF-16 CSV file, and the data should look like this:

2/13/2015 10:12 AM  Info    10.140.13.101   <<1423839912177>>   OpID=99999999 PID=009D NodeID=CC  Store#=0971   10:02:36.17 Fri 02-13-2015    adxcsu0l 3 5 samsyslg.jar {vA0uFbU05eWE7CVrMxNU+x6hylM+o7WdFJYA2vs/Tkk=}

Any idea how I might be able to get Splunk to recognize the data in the fields?

Thanks so much.

0 Karma

meenal901
Communicator

If you have Microsoft Excel, open the file and again save is as "CSV". Make sure not to choose "Mac OS".
This means Splunk still cannot read your csv as csv.
In addition, add charset in props.conf while importing this data.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Did you set the charset in props.conf on the forwarder to UTF-16 for that file?

jterry
Splunk Employee
Splunk Employee

does Splunk Enterprise do the same thing?

0 Karma

jsven7
Communicator

Yes same here I'm having the same problem. Really weird.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...