<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allowed characters for metadata fields source and sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469282#M80740</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults count=256
| streamstats count as code
| eval ascii=printf("%c",code)
| stats values(ascii) as ascii
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding"&gt;Configure character set encoding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the encoding is correct, there should be no problem.&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2020 01:41:54 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-02-09T01:41:54Z</dc:date>
    <item>
      <title>Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469281#M80739</link>
      <description>&lt;P&gt;My question is simple: which characters are allowed for the values of the metadata fields &lt;CODE&gt;source&lt;/CODE&gt; and &lt;CODE&gt;sourcetype&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;I could not find any documentation on this.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 00:20:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469281#M80739</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2020-02-09T00:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469282#M80740</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults count=256
| streamstats count as code
| eval ascii=printf("%c",code)
| stats values(ascii) as ascii
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding"&gt;Configure character set encoding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the encoding is correct, there should be no problem.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 01:41:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469282#M80740</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-09T01:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469283#M80741</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configureindex-timefieldextraction"&gt;Field name syntax restrictions&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field name syntax restrictions
You can assign field names as follows:

Valid characters for field names are a-z, A-Z, 0-9, or _ .
Field names cannot begin with 0-9 or _ . Splunk reserves leading underscores for its internal variables.
Avoid assigning field names that match any of the default field names.
Do not assign field names that contain international characters.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 09 Feb 2020 01:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469283#M80741</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-09T01:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469284#M80742</link>
      <description>&lt;P&gt;@to4kawa The link you posted does not seem to apply. I am not asking about field names, but field values. I am going to update the question to make this more clear.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 01:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469284#M80742</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2020-02-09T01:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469285#M80743</link>
      <description>&lt;P&gt;@to4kawa I am not sure you understood my question. Also, you should explain (in detail) how the search you posted just now helps answer my question.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 01:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469285#M80743</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2020-02-09T01:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469286#M80744</link>
      <description>&lt;P&gt;I'm sorry I couldn't meet your request.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 02:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469286#M80744</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-09T02:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed characters for metadata fields source and sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469287#M80745</link>
      <description>&lt;P&gt;The values you assign to those fields are arbitrary strings. They can contain any characters within the specified supported character  (more info on that here: &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 16:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Allowed-characters-for-metadata-fields-source-and-sourcetype/m-p/469287#M80745</guid>
      <dc:creator>acfecondo75</dc:creator>
      <dc:date>2020-02-10T16:07:27Z</dc:date>
    </item>
  </channel>
</rss>

