Is there a command or app that will decode base64 and detect the correct charset to output to?
Currently, I'm currently unable to decode to UTF-16LE.
Splunk wants to decode UTF-8.
In my current role, I cannot edit any .conf files.
Those are administrated by a server team.
If there is an app, I can request it be installed, else I'm working solely out of the SPL.
There are couple of apps which can manage e.g. base64 encoding. Here is one which I have used https://splunkbase.splunk.com/app/5565
When you have issues with windows character sets, you must add character set information into UF’s props.conf. There are some examples in community and this is also described on docs.