Monitoring Splunk

UTF8Processor warning message

ollie920049
Path Finder

Hi there,

I have CHARSET = UTF-16LE enforced in props.conf for all universal forwarders.

For UniForwarder -> Indexer this all works correctly. However, for UniForwarder -> HeavyForwareder -> Indexer this causes an WARN log entry for each processed event on the heavy forwarder:

12-04-2014 15:27:48.026 +0000 WARN UTF8Processor - Using charset UTF-8, as the monitor is believed over the raw text which may be UTF-16LE

Any ideas what I can do to fix this? It's currently being indexed correctly, but generating 1000's of WARN's a minute.

Thanks in advance

Tags (2)

gavsdavs_GR
Path Finder

Your HF is parsing, whatever it is you have set up for the sourcetype on the indexer needs to be on the HF too.

Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...