Splunk Enterprise

Why file encoding is not supported, only utf-8 encoded files are supported splunk?

Simone
Explorer

Hello,

I have installed the splunk enterprise free version on my pc and i have installed the app Splunk app for lookup file edting but unfortunatly doesn't works.

When i try to upload a file .csv i have the following error "File is binary or file encoding is not supported, only utf-8 encoded files are supported splunk".

I tried to change the permission on the app's folder on windows but i did not resolve the problem.

I tested with a very easy csv, and this one is the result:

Simone_0-1690794125363.png

In the csv the column test3,test,test2 were divided. I saved the .csv in all format.

Thanks for the support!

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Open the file with notepad++ to confirm it's truly in CSV format.  If the values are not separated by commas then it's not a CSV file.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The file's encoding has nothing to do with its permissions.  If Splunk finds binary or non-UTF-8 data then the *content* needs to change rather than the access rights.

Similarly, putting ".csv" on the end of a file name does not make the file a CSV file.  It's the *content* that matters.  A CSV file needs to have each column separated from other columns by a comma.  If you create the file using a spreadsheet program like Excel, be sure to save the file in CSV format.  "All" is not a format.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Simone
Explorer

Thanks for the answer.

"All" format means that i tried CSV (MS-Dos), CSV (Macintosh), CSV (comma delimited), etc.

My csv is not separate by comma, it's a simple .csv:

Simone_0-1690812156831.png

I changed the permission after read this topic: https://community.splunk.com/t5/Getting-Data-In/once-more-about-quot-File-is-binary-or-file-encoding...

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Open the file with notepad++ to confirm it's truly in CSV format.  If the values are not separated by commas then it's not a CSV file.

---
If this reply helps you, Karma would be appreciated.

Simone
Explorer

You are right!

i change the configuration on my pc.

Thanks for the support 🙂

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...