<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UTF-16 File Format-Data Ingestion in Installation</title>
    <link>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581025#M11057</link>
    <description>&lt;P&gt;Have you tried CHARSET on props.conf on UF/source node?&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf&lt;/A&gt;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jan 2022 21:11:46 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-13T21:11:46Z</dc:date>
    <item>
      <title>UTF-16 File Format-Data Ingestion</title>
      <link>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581020#M11056</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I know ....SPLUNK needs to have UTF-8 data format to ingest data into SPLUNK. But I have some XML files with UTF-16 format. Are there any ways we can ingest UTF-16 formatted files? Any help will be appreciated ...thank you so much.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 20:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581020#M11056</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-01-13T20:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: UTF-16 File Format-Data Ingestion</title>
      <link>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581025#M11057</link>
      <description>&lt;P&gt;Have you tried CHARSET on props.conf on UF/source node?&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf&lt;/A&gt;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 21:11:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581025#M11057</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-13T21:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: UTF-16 File Format-Data Ingestion</title>
      <link>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581026#M11058</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much appreciate your response. I tried with following codes, but not working. Any help will be highly appreciated. Thank you so much again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;[ &amp;lt;SOURCETYPE NAME&amp;gt; ]&lt;/P&gt;&lt;P class=""&gt;SHOULD_LINEMERGE=true&lt;/P&gt;&lt;P class=""&gt;LINE_BREAKER=([\r\n]+)&lt;/P&gt;&lt;P class=""&gt;NO_BINARY_CHECK=true&lt;/P&gt;&lt;P class=""&gt;CHARSET=UTF-8&lt;/P&gt;&lt;P class=""&gt;disabled=false&lt;/P&gt;&lt;P class=""&gt;detect_trailing_nulls=false&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 21:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581026#M11058</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-01-13T21:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: UTF-16 File Format-Data Ingestion</title>
      <link>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581368#M11062</link>
      <description>&lt;P&gt;CHARSET option must be on source system (UF) and that must restated after props.conf change.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 17:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UTF-16-File-Format-Data-Ingestion/m-p/581368#M11062</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-17T17:43:08Z</dc:date>
    </item>
  </channel>
</rss>

