Getting Data In

SplunkForwarder garble events with \x00

berndg
Engager

I observe a strange behavior with one of out UniversalForwarders.

First I've added a new logfile on the forwarder with CLI. Events looks good on a search.

After that I'vre removed the monitor and re-added with "-sourcetype cerberus-ftp".

Result: Events are not encoded anymore:

\x00[\x002\x000\x001\x003\x00-\x000\x007\x00-\x000\x004\x00 \x001\x004\x00:\x002\x005\x00:\x003\x003\x00]\x00:\x00C\x00O\x00N\x00N\x00E\x00C\x00T\x00 \x00[\x00 \x00 \x001\x003\x007\x000\x00]\x00 \x00-\x00 \x00T\x00h\x00e\x00 \x00c\x00l\x00i\x00e\x00n\x00t\x00 \x00c\x00l\x00o\x00s\x00e\x00d\x00 \x00t\x00h\x00e\x00 \x00c\x00o\x00n\x00n\x00e\x00c\x00t\x00i\x00o\x00n\x00

I've tried to add "CHARSET = UTF-16" to props.conf. Nothing changed.

If I remove the monitor and add without the sourcetype specified the event is displayed correctly.

Our Setup:

  • Windows SplunkForwarder 5.0.2
  • Linux Indexer 5.0.1
  • Linux SearchHead 5.0.1

Some ideas how to fix the encoding and why the specification of the sourcetype change it?

josh_beverly
Explorer

Did you ever get a solution to this? Also, I assume this is for logs for cerberus ftp? If so could you please provide your solution for getting the logs from cerberus?

Thanks,

0 Karma

russellliss
Path Finder

I had the exact same issue. No matter what I changed the sourcetype to, unless it was "server", which is the default, I got those characters coming through.

I even tried the charset suggestion from here http://answers.splunk.com/answers/24484/sql-server-errorlog, but then on one server I started to get even stranger results.

Only seems to happen with the Cerberus FTP log file though.

0 Karma

jonthanze
Explorer

Can you please share your input and props conf files ? I have the same issue with the same architecture and i cannot solve it

thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

Ready to make your IT operations smarter and more efficient? Discover how to automate Splunk alerts with Red ...