Getting Data In

Encoding for forwarded data

andrey2007
Contributor

I have files in CP866 encoding. For indexing them in Splunk i made _russian-CP866.ngram file and changed props.conf this way
[host::]
CHARSET=russian-CP866
What should i do for indexing files in CP866 encoding, which are forwarded by universalforwarder from remote host?

Tags (2)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

CHARSET must be specified on the input, i.e., that config must be on the Universal Forwarder.

0 Karma

andrey2007
Contributor

Where can i do it? In Universal Forwarder there is no ngrams-model folder.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...