Getting Data In

Allowed characters for metadata fields source and sourcetype

helge
Builder

My question is simple: which characters are allowed for the values of the metadata fields source and sourcetype?

I could not find any documentation on this.

0 Karma
1 Solution

acfecondo75
Path Finder

The values you assign to those fields are arbitrary strings. They can contain any characters within the specified supported character (more info on that here: https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding)

View solution in original post

acfecondo75
Path Finder

The values you assign to those fields are arbitrary strings. They can contain any characters within the specified supported character (more info on that here: https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Configurecharactersetencoding)

to4kawa
Ultra Champion
| makeresults count=256
| streamstats count as code
| eval ascii=printf("%c",code)
| stats values(ascii) as ascii

Configure character set encoding

If the encoding is correct, there should be no problem.

0 Karma

helge
Builder

@to4kawa I am not sure you understood my question. Also, you should explain (in detail) how the search you posted just now helps answer my question.

0 Karma

to4kawa
Ultra Champion

I'm sorry I couldn't meet your request.

0 Karma

to4kawa
Ultra Champion

Field name syntax restrictions

Field name syntax restrictions
You can assign field names as follows:

Valid characters for field names are a-z, A-Z, 0-9, or _ .
Field names cannot begin with 0-9 or _ . Splunk reserves leading underscores for its internal variables.
Avoid assigning field names that match any of the default field names.
Do not assign field names that contain international characters.
0 Karma

helge
Builder

@to4kawa The link you posted does not seem to apply. I am not asking about field names, but field values. I am going to update the question to make this more clear.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...