Getting Data In

Can 1 sourcetype have 2 CHARSET?

muizash
Path Finder

I have a sourcetype named "abc"
It is configured to CHARSET=UTF_8

When I see the events, some events split because of no reason and when i check those particular events, they have encoding of utf-16.

What do I do?

0 Karma

techiesid
SplunkTrust
SplunkTrust

Hi,

Can you do the below settings and see whether its solving your issue,

[abc]
CHARSET=AUTO

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configurecharactersetencoding#Automatically_...

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...