Getting Data In

Can 1 sourcetype have 2 CHARSET?

muizash
Path Finder

I have a sourcetype named "abc"
It is configured to CHARSET=UTF_8

When I see the events, some events split because of no reason and when i check those particular events, they have encoding of utf-16.

What do I do?

0 Karma

techiesid
SplunkTrust
SplunkTrust

Hi,

Can you do the below settings and see whether its solving your issue,

[abc]
CHARSET=AUTO

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Configurecharactersetencoding#Automatically_...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...