Monitoring Splunk

UTF8Processor warning message

ollie920049
Path Finder

Hi there,

I have CHARSET = UTF-16LE enforced in props.conf for all universal forwarders.

For UniForwarder -> Indexer this all works correctly. However, for UniForwarder -> HeavyForwareder -> Indexer this causes an WARN log entry for each processed event on the heavy forwarder:

12-04-2014 15:27:48.026 +0000 WARN UTF8Processor - Using charset UTF-8, as the monitor is believed over the raw text which may be UTF-16LE

Any ideas what I can do to fix this? It's currently being indexed correctly, but generating 1000's of WARN's a minute.

Thanks in advance

Tags (2)

gavsdavs_GR
Path Finder

Your HF is parsing, whatever it is you have set up for the sourcetype on the indexer needs to be on the HF too.

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...