I've got email subjects extracted into a field, which are encoded in UTF-8 or ISO-8859-*
What would be the best way to convert these into a readable format?
You can configure character set encoding. Here is the manual page that describes how:
Let's say that we want to create a field which is simply an original field decoded into ASCII and we want that process to happen internally within Splunk. How do we do that?
It was not exactly was I was looking for. The logfile is in ASCII, but it contains fields that are MIME encoded.
To solve the problem I wrote an external command, that decodes MIME fields into utf-8.
Get the code here:
Try MIME Decoder TA add-on:https://splunkbase.splunk.com/app/5116/