French users : how to get "é" instead of "/xE9"


Hi, I write this question in English to allow evry users to access it.

I get logs from Windows application installed on a french Windows system.
When Splunk indexes these logs, french caracters are displayed with there code not the caracter itself.
I Found that it should be du to the character encoding utf-8 instead of latin-1.

Does somedy knows where I can change this encoding and what should be the result over my splunk install ?


Tags (2)
0 Karma

Splunk Employee
Splunk Employee

Edit $SPLUNK_HOME/etc/system/local/props.conf and add the following stanza:

CHARSET = latin-1

If you have a specific application, perform the same modification under $SPLUNK_HOME/etc/apps/<APP_NAME>/local/props.conf

Then restart Splunk.

.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!