Security

how to set encoding of event on indexer cluster

xsstest
Communicator

hi,Please forgive my English

In my indexer cluster,The Chinese in the event shows that there is a coding problem, showing something like hexadecimal.

\x3A\xAB

I tried to set the sourcetype encoding on the index master node. Set up as follows:

vim /opt/splunk/etc/master-apps/_cluster/local/props.conf

[Firewall]
CHARSET = AUTO

Then distribute the bundle. And did not play any effect

I have also tried to adapt to the Chinese code:

[Firewall]
CHARSET = HZ

But it still does not have any effect

Why?
Is my method wrong?

Tags (1)
0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Where do you collect the data from? You should set the character encoding on the server / endpoint where you have the inputs.conf configured.

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Where do you collect the data from? You should set the character encoding on the server / endpoint where you have the inputs.conf configured.

0 Karma

xsstest
Communicator

Why is it encoding in inputs.conf, not props.conf? Are there any splunk documentation?

0 Karma

MuS
Legend

Hi xsstest,

I reckon this is still the best place to read about Where do I configure my Splunk settings? http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings but if you prefer the docs page here it is http://docs.splunk.com/Documentation/Splunk/latest/Admin/Configurationparametersandthedatapipeline

cheers, MuS

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Updated the comment, you're correct. It should be in props.conf. Set this on your UF where you ingest this and try: https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Data/Configurecharactersetencoding

0 Karma

xsstest
Communicator

The UF forwarding data to the indexer cluster. I configure the encoding on all the indexers。Distribute bundles through the master node

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Encoding should be set on the UF, in the [inputs] configuration with a props on the UF.

This is because the data is already indexed on your indexers, and Splunk needs to understand what the encoding is before it indexes the data.

0 Karma

xsstest
Communicator

the Firewall is a sourcetype~

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...