Splunk Enterprise Security

Using Umlauts in the Correlation Search Name breaks the Correlation Search edit view

martin_mueller
SplunkTrust
SplunkTrust

Using ESS 3.1.1 on Splunk 6.1.4, I can create a correlation search with an Umlaut in its name, such as "my cörrelation search". Saving it works fine, and it'll execute according to its schedule, generating notable events and emails and whatnot. Hence Splunk itself can handle Umlauts in search IDs well.

However, I cannot open the correlation search editor for this after the initial save. In the JS Console I get a 500 error from https://splunk-host:8000/de-DE/custom/SA-ThreatIntelligence/correlation_searches/get_search?output_m..., opening that in my browser is showing KeyError: u'\xf6', the hex code for ö.

It'd be nice to either enable this Python script to work with Umlauts and similar non-standard characters, or at least to have the Correlation Search editor stop the user from creating such a Correlation Search in the first place.

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Unfortunately, ES is not totally i18n or l10n compliant, and so this is a known issue. The workaround is to "not use them" in the interim, but you should also file an enhancement request (aka support case with priority level 4) and ask to have this added in, with bonus points for documenting your pains, if you would like this support added in the future. You can reference SOLNESS-6641. (Of course, in the case of your particular issue, I am sure based on the timing that you've already done that... so now you can just advocate for your germanic brethren to rise up and demand the ability to fully express themselves in correlation search names.)

View solution in original post

David
Splunk Employee
Splunk Employee

Unfortunately, ES is not totally i18n or l10n compliant, and so this is a known issue. The workaround is to "not use them" in the interim, but you should also file an enhancement request (aka support case with priority level 4) and ask to have this added in, with bonus points for documenting your pains, if you would like this support added in the future. You can reference SOLNESS-6641. (Of course, in the case of your particular issue, I am sure based on the timing that you've already done that... so now you can just advocate for your germanic brethren to rise up and demand the ability to fully express themselves in correlation search names.)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...