Monitoring Splunk

UTF8Processor warning message

ollie920049
Path Finder

Hi there,

I have CHARSET = UTF-16LE enforced in props.conf for all universal forwarders.

For UniForwarder -> Indexer this all works correctly. However, for UniForwarder -> HeavyForwareder -> Indexer this causes an WARN log entry for each processed event on the heavy forwarder:

12-04-2014 15:27:48.026 +0000 WARN UTF8Processor - Using charset UTF-8, as the monitor is believed over the raw text which may be UTF-16LE

Any ideas what I can do to fix this? It's currently being indexed correctly, but generating 1000's of WARN's a minute.

Thanks in advance

Tags (2)

gavsdavs_GR
Path Finder

Your HF is parsing, whatever it is you have set up for the sourcetype on the indexer needs to be on the HF too.

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...