Splunk Search

Can we change the character code in export format ? (検索結果ダウンロード時の文字コード変更について)

sunrise
Contributor

Splunkでは検索結果をCSVやrawフォーマットでダウンロードすることが出来ますが、
その際、文字コードをデフォルトのUTF-8から別のもの(SJIS, EUC, MS932等)へと変更することは可能でしょうか?
Splunkが取り込んだデータがUTF-8形式で保管されているのはわかりますが、
Windows系のデスクトップでファイルを開いた時、フォーマットを焼き直すなどの二度手間になってしまいます。


Hi Splunkers,

After getting search results, we can export search results by Splunk.
In default setting, that character code is UTF-8.
Can we change this character code to others(SJIS, EUC, MS932 etc) ?
I know that Splunk restains data as UTF-8 format,
but most of Japanese PC are some kinds of Windows system which are on SJIS base.
So we always bothered to open downloaded files from Splunk.

Thank you for your help.

1 Solution

Suda
Communicator

sunriseさん、こんにちは


エクスポート時に文字コードをUTF-8以外に変更する機能はSplunk 6.0.3には提供されていないと思います。
一方で、Excel Export Appを利用すれば、文字コードを変換する必要はありません。お試しください。


I believe Splunk 6.0.3 and lower versions don't have any function to specify character encoding type to export results.
It is always UTF-8.
But if you use "Excel Export App" to export search results, you don't need to convert character encoding.


Happy splunking!!

Excel Export App

View solution in original post

0 Karma

Suda
Communicator

sunriseさん、こんにちは


エクスポート時に文字コードをUTF-8以外に変更する機能はSplunk 6.0.3には提供されていないと思います。
一方で、Excel Export Appを利用すれば、文字コードを変換する必要はありません。お試しください。


I believe Splunk 6.0.3 and lower versions don't have any function to specify character encoding type to export results.
It is always UTF-8.
But if you use "Excel Export App" to export search results, you don't need to convert character encoding.


Happy splunking!!

Excel Export App

0 Karma

sunrise
Contributor

Thank you, Suda. I'll try that app.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...