Getting Data In

Overlapping Inputs With Different Charset

tgiles
Path Finder

Hi, All. I have an overlapping path issue in Windows that I might need some assist on.

I have the contents of two directories which need monitoring (all files have the .log extension):

  • C:\Program Files\MyApp\Client\ConnLog
  • C:\Program Files\MyApp\Client\report

Looks like Splunk has issues with overlapping monitor inputs[1], so I can't monitor the directories with separate input stanzas. The files in the 'report' directory have (for whatever reason) ISO-8859-1 encoding. Splunk requires a separate props.conf directive so the log files are read correctly.

I'm unable to set the input to the parent directory (like "C:\Program Files\MyApp\Client") since the character set change in the report/ directory. Also, there are other files which I don't want to read from the parent directory.

Here's an example (not-really-working) configuration I'm using at the moment.

Have any thoughts on how I will be able to read the contents of both directories as well as read the report directory with the appropriate character set intact?

-- inputs.conf

[monitor://C:\Program Files\MyApp\Client\ConnLog]
sourcetype = conn_log
followTail = 1
crcSalt = <source>

[monitor://C:\Program Files\MyApp\Client\report]
sourcetype = report_log
followTail = 1
crcSalt = <source>

-- props.conf

[source::C:\Program Files\MyApp\Client\report]
CHARSET = ISO-8859-1

[1] http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Tags (3)
0 Karma

bojanz
Communicator

This should work, you can maybe try setting the character set by using sourcetype instead of source:

[report_log]
CHARSET = ISO-8859-1

Make sure that you added the props.conf file on the forwarder, not the indexer.

0 Karma

tgiles
Path Finder

hi, Thanks for the input.

unfortunately, adding the CHARSET directive into the sourcetype does nothing for me- the entries show up as line noise, just like if the directive wasn't set.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...