<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search with utf-8 codes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-with-utf-8-codes/m-p/104091#M183139</link>
    <description>&lt;P&gt;Splunk can be configured for the proper character encoding for an input using the &lt;CODE&gt;CHARSET&lt;/CODE&gt; option of &lt;CODE&gt;props.conf&lt;/CODE&gt;.   &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Propsconf"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;A configuration similar to this may work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[glassfish]
CHARSET = UTF-8 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, review &lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Data/Configurecharactersetencoding"&gt;http://www.splunk.com/base/Documentation/4.2.1/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Character encoding changes obviously only affect data that is loaded into Splunk after the change is made.  It is not retroactive to already-indexed data.&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2011 19:15:17 GMT</pubDate>
    <dc:creator>dwaddle</dc:creator>
    <dc:date>2011-05-18T19:15:17Z</dc:date>
    <item>
      <title>Search with utf-8 codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-with-utf-8-codes/m-p/104090#M183138</link>
      <description>&lt;P&gt;In the loggfile:&lt;/P&gt;

&lt;P&gt;[#|2011-05-18T11:03:35.375+0200|SEVERE|sun-appserver2.1|com.sun.xml.ws.server.sei.EndpointMethodHandler|_ThreadID=16;_ThreadName=httpSSLWorkerThread-8080-2;_RequestID=93413f1f-5ed3-488e-8843-3872c4d07991;|Kan ikke oppdatere et låst oppdrag&lt;BR /&gt;
javax.xml.ws.soap.SOAPFaultException: Kan ikke oppdatere et låst oppdrag&lt;/P&gt;

&lt;P&gt;("Kan ikke oppdatere låst oppdrag")&lt;/P&gt;

&lt;P&gt;In the search result and in the "show source":&lt;/P&gt;

&lt;P&gt;[#|2011-05-18T11:03:35.375+0200|SEVERE|sun-appserver2.1|com.sun.xml.ws.server.sei.EndpointMethodHandler|_ThreadID=16;_ThreadName=httpSSLWorkerThread-8080-2;_RequestID=93413f1f-5ed3-488e-8843-3872c4d07991;|Kan ikke oppdatere et l\xE5st oppdrag&lt;BR /&gt;
javax.xml.ws.soap.SOAPFaultException: Kan ikke oppdatere et l\xE5st oppdrag&lt;/P&gt;

&lt;P&gt;("Kan ikke oppdatere et l\xE5st oppdrag")&lt;/P&gt;

&lt;P&gt;What can I do to get "låst" instead of "l\xE5st", alternatively how can I search for "l\xE5st"?&lt;/P&gt;

&lt;P&gt;Thanks and regards,&lt;BR /&gt;
Bård Tørustad&lt;BR /&gt;
Research Council of Norway&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-with-utf-8-codes/m-p/104090#M183138</guid>
      <dc:creator>torustad</dc:creator>
      <dc:date>2020-09-28T09:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Search with utf-8 codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-with-utf-8-codes/m-p/104091#M183139</link>
      <description>&lt;P&gt;Splunk can be configured for the proper character encoding for an input using the &lt;CODE&gt;CHARSET&lt;/CODE&gt; option of &lt;CODE&gt;props.conf&lt;/CODE&gt;.   &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Propsconf"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;A configuration similar to this may work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[glassfish]
CHARSET = UTF-8 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, review &lt;A href="http://www.splunk.com/base/Documentation/4.2.1/Data/Configurecharactersetencoding"&gt;http://www.splunk.com/base/Documentation/4.2.1/Data/Configurecharactersetencoding&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Character encoding changes obviously only affect data that is loaded into Splunk after the change is made.  It is not retroactive to already-indexed data.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2011 19:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-with-utf-8-codes/m-p/104091#M183139</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-05-18T19:15:17Z</dc:date>
    </item>
  </channel>
</rss>

