Getting Data In

Overlapping Inputs With Different Charset

tgiles
Path Finder

Hi, All. I have an overlapping path issue in Windows that I might need some assist on.

I have the contents of two directories which need monitoring (all files have the .log extension):

  • C:\Program Files\MyApp\Client\ConnLog
  • C:\Program Files\MyApp\Client\report

Looks like Splunk has issues with overlapping monitor inputs[1], so I can't monitor the directories with separate input stanzas. The files in the 'report' directory have (for whatever reason) ISO-8859-1 encoding. Splunk requires a separate props.conf directive so the log files are read correctly.

I'm unable to set the input to the parent directory (like "C:\Program Files\MyApp\Client") since the character set change in the report/ directory. Also, there are other files which I don't want to read from the parent directory.

Here's an example (not-really-working) configuration I'm using at the moment.

Have any thoughts on how I will be able to read the contents of both directories as well as read the report directory with the appropriate character set intact?

-- inputs.conf

[monitor://C:\Program Files\MyApp\Client\ConnLog]
sourcetype = conn_log
followTail = 1
crcSalt = <source>

[monitor://C:\Program Files\MyApp\Client\report]
sourcetype = report_log
followTail = 1
crcSalt = <source>

-- props.conf

[source::C:\Program Files\MyApp\Client\report]
CHARSET = ISO-8859-1

[1] http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

Tags (3)
0 Karma

bojanz
Communicator

This should work, you can maybe try setting the character set by using sourcetype instead of source:

[report_log]
CHARSET = ISO-8859-1

Make sure that you added the props.conf file on the forwarder, not the indexer.

0 Karma

tgiles
Path Finder

hi, Thanks for the input.

unfortunately, adding the CHARSET directive into the sourcetype does nothing for me- the entries show up as line noise, just like if the directive wasn't set.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...