Splunk Search

File upload with user defined charset does not recognized German umlaute

schomar
New Member

We are trying to upload a text file with German text, but the German umlaute are not recognized

Manual file upload (only works on second attempts)

Procedure:
Add data
1. Select Source (file) -> next
2. Set Source Type
(custom)
- line break is working
- charset MS-ANSI German umlaute are not recognized -> next
3. Input settings
...

However, still within the wizard ...
... when we select in the wizard step 3. Input settings back and next ...
... the charset is recognized and German umlaute is recognized!

automatic file monitoring (does not work either)

Monitoring a folder for input does not recognize the charset MS-ANSI and German umlaute at all

Source type used

CHARSET = MS-ANSI
LINE_BREAKER = (ENDG.*LTIGE BEDINGUNGEN)
NO_BINARY_CHECK = true
TRUNCATE = 1000000
category = Custom
disabled = false
pulldown_type = true
SHOULD_LINEMERGE = false

Anybody encountered this weird issue?

Tags (1)
0 Karma
1 Solution

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

schomar
New Member

There was no timestamp defined in the source type,

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...