Alerting

search error for sendemail

johnnyt
New Member

Dear

I search cmd:

sourcetype="access_combined" clientip="192.0.1.42" | sendemail to="teng.johnny@msa.hinet.net" format=html subject=myresults server=msa.hinet.net

the error

Input is not proper UTF-8, indicate encoding ! Bytes: 0xB3 0x73 0xBD 0x75, line 165, column 37

0 Karma

jrodman
Splunk Employee
Splunk Employee

Not really sure what component is not liking its input. My first guess is the python mail sender is failing to handle the raw data being passed to it by splunk.

Does this command work with other data?

If you output that data to a csv file, is there anything strange in it?

Is there more about the error, for example an indication of what component is emitting the error, or more about how the error is presented?

Is it possible that those are "smart quotes" somehow?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...