Getting Data In

Can 1 sourcetype have 2 CHARSET?

muizash
Path Finder

I have a sourcetype named "abc"
It is configured to CHARSET=UTF_8

When I see the events, some events split because of no reason and when i check those particular events, they have encoding of utf-16.

What do I do?

0 Karma

techiesid
SplunkTrust
SplunkTrust

Hi,

Can you do the below settings and see whether its solving your issue,

[abc]
CHARSET=AUTO

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configurecharactersetencoding#Automatically_...

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...