<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can 1 sourcetype have 2 CHARSET? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-1-sourcetype-have-2-CHARSET/m-p/493485#M84320</link>
    <description>&lt;P&gt;I have a sourcetype named "abc"&lt;BR /&gt;
It is configured to CHARSET=UTF_8&lt;/P&gt;

&lt;P&gt;When I see the events, some events split because of no reason and when i check those particular events, they have encoding of utf-16.&lt;/P&gt;

&lt;P&gt;What do I do?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Nov 2019 01:58:39 GMT</pubDate>
    <dc:creator>muizash</dc:creator>
    <dc:date>2019-11-26T01:58:39Z</dc:date>
    <item>
      <title>Can 1 sourcetype have 2 CHARSET?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-1-sourcetype-have-2-CHARSET/m-p/493485#M84320</link>
      <description>&lt;P&gt;I have a sourcetype named "abc"&lt;BR /&gt;
It is configured to CHARSET=UTF_8&lt;/P&gt;

&lt;P&gt;When I see the events, some events split because of no reason and when i check those particular events, they have encoding of utf-16.&lt;/P&gt;

&lt;P&gt;What do I do?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 01:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-1-sourcetype-have-2-CHARSET/m-p/493485#M84320</guid>
      <dc:creator>muizash</dc:creator>
      <dc:date>2019-11-26T01:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can 1 sourcetype have 2 CHARSET?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-1-sourcetype-have-2-CHARSET/m-p/493486#M84321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Can you do the below settings and see whether its solving your issue,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[abc]
CHARSET=AUTO
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configurecharactersetencoding#Automatically_specify_a_character_set"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configurecharactersetencoding#Automatically_specify_a_character_set&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 07:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-1-sourcetype-have-2-CHARSET/m-p/493486#M84321</guid>
      <dc:creator>techiesid</dc:creator>
      <dc:date>2019-11-26T07:08:20Z</dc:date>
    </item>
  </channel>
</rss>

