Getting Data In

Splunk on OS's other than English

des_esse_err
Explorer

Hello,

I installed Splunk (full instance and/or universal forwarder) on OS's in French.
Some stuff will obviously work (such as pulling information from the Windows event logs), but for other stuff, it's less "obvious".
For example, I'm thinking of performance counters. In the French version of the OS, the counter names are different, and contain accents, which Splunk does not recognize. When starting the UF with a localized perfmon.conf file with french counter names, it will error out and report it cannot find the counters (because, in the names it looks for, it will drop accented letters and thus, the counter name does indeed not match).
I've gone through some research, but have not really found anything on this type of thing, beside character set settings in props.conf.
Any pointer or experience on this matter ?
Also, what's the idea as far as distributing conf files for OS'es which are in different languages ? Have different ServerClass'es based on language in order to distribute the appropriate conf file ?

Many thanks.

Kind regards,

David

0 Karma

ClementG
Path Finder

Hello David,

Did you save the file with a Unicode encoding ?

Otherwise you can try to put these in your perfmon.conf.

[PERFMON:CPU Load]
counters = 6;142
disabled = 0
instances = _Total
interval = 10
object = 238

[PERFMON:Available Memory]
counters = 26
disabled = 0
interval = 10
object = 4

[PERFMON:Free Disk Space]
counters = 410;408
disabled = 0
instances = _Total
interval = 10
object = 236

[PERFMON:Network Interface]
counters = 264;506
disabled = 0
instances = *
interval = 10
object = 510

Regards

0 Karma

ClementG
Path Finder

By default the encoding used is ANSI and doesn't support any french accent.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Are there problems with splunk isng utf-8 characters with perfmon, or are you asking if the file was saved as utf-16 (which certainly won't work.)

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...