Splunk Enterprise Security

Using Umlauts in the Correlation Search Name breaks the Correlation Search edit view

martin_mueller
SplunkTrust
SplunkTrust

Using ESS 3.1.1 on Splunk 6.1.4, I can create a correlation search with an Umlaut in its name, such as "my cörrelation search". Saving it works fine, and it'll execute according to its schedule, generating notable events and emails and whatnot. Hence Splunk itself can handle Umlauts in search IDs well.

However, I cannot open the correlation search editor for this after the initial save. In the JS Console I get a 500 error from https://splunk-host:8000/de-DE/custom/SA-ThreatIntelligence/correlation_searches/get_search?output_m..., opening that in my browser is showing KeyError: u'\xf6', the hex code for ö.

It'd be nice to either enable this Python script to work with Umlauts and similar non-standard characters, or at least to have the Correlation Search editor stop the user from creating such a Correlation Search in the first place.

0 Karma
1 Solution

David
Splunk Employee
Splunk Employee

Unfortunately, ES is not totally i18n or l10n compliant, and so this is a known issue. The workaround is to "not use them" in the interim, but you should also file an enhancement request (aka support case with priority level 4) and ask to have this added in, with bonus points for documenting your pains, if you would like this support added in the future. You can reference SOLNESS-6641. (Of course, in the case of your particular issue, I am sure based on the timing that you've already done that... so now you can just advocate for your germanic brethren to rise up and demand the ability to fully express themselves in correlation search names.)

View solution in original post

David
Splunk Employee
Splunk Employee

Unfortunately, ES is not totally i18n or l10n compliant, and so this is a known issue. The workaround is to "not use them" in the interim, but you should also file an enhancement request (aka support case with priority level 4) and ask to have this added in, with bonus points for documenting your pains, if you would like this support added in the future. You can reference SOLNESS-6641. (Of course, in the case of your particular issue, I am sure based on the timing that you've already done that... so now you can just advocate for your germanic brethren to rise up and demand the ability to fully express themselves in correlation search names.)

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...