Hello,
I know ....SPLUNK needs to have UTF-8 data format to ingest data into SPLUNK. But I have some XML files with UTF-16 format. Are there any ways we can ingest UTF-16 formatted files? Any help will be appreciated ...thank you so much.
Have you tried CHARSET on props.conf on UF/source node? https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
r. Ismo
Hello,
Thank you so much appreciate your response. I tried with following codes, but not working. Any help will be highly appreciated. Thank you so much again.
[ <SOURCETYPE NAME> ]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
disabled=false
detect_trailing_nulls=false
CHARSET option must be on source system (UF) and that must restated after props.conf change.