Hi,
Log format is JSON
I have a Field named Organization
Now when Organization = "Systèmes" , this will have the following consequences
--
When doing a search with Organization = "Systèmes" (and doing e.g. a table output), I get no results
When doing a search with Organization = Syst* (and doing e.g. a table output), I get results
--
I am wondering why Splunk would not recognize this è in the search ...
I read different topics where CHARSET in props.conf file was suggested, but should Splunk not recognize this è by default?
And what would be the solution to get this recognized by Splunk by Default?
Thanks in advance!
Edwin