Installation

UTF-16 File Format-Data Ingestion

SplunkDash
Motivator

Hello,

I know ....SPLUNK needs to have UTF-8 data format to ingest data into SPLUNK. But I have some XML files with UTF-16 format. Are there any ways we can ingest UTF-16 formatted files? Any help will be appreciated ...thank you so much.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you tried CHARSET on props.conf on UF/source node? https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
r. Ismo

SplunkDash
Motivator

Hello,

Thank you so much appreciate your response. I tried with following codes, but not working. Any help will be highly appreciated. Thank you so much again.

 

[ <SOURCETYPE NAME> ]

SHOULD_LINEMERGE=true

LINE_BREAKER=([\r\n]+)

NO_BINARY_CHECK=true

CHARSET=UTF-8

disabled=false

detect_trailing_nulls=false

0 Karma

isoutamo
SplunkTrust
SplunkTrust

CHARSET option must be on source system (UF) and that must restated after props.conf change.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...