Splunk Search

File upload with user defined charset does not recognized German umlaute

schomar
New Member

We are trying to upload a text file with German text, but the German umlaute are not recognized

Manual file upload (only works on second attempts)

Procedure:
Add data
1. Select Source (file) -> next
2. Set Source Type
(custom)
- line break is working
- charset MS-ANSI German umlaute are not recognized -> next
3. Input settings
...

However, still within the wizard ...
... when we select in the wizard step 3. Input settings back and next ...
... the charset is recognized and German umlaute is recognized!

automatic file monitoring (does not work either)

Monitoring a folder for input does not recognize the charset MS-ANSI and German umlaute at all

Source type used

CHARSET = MS-ANSI
LINE_BREAKER = (ENDG.*LTIGE BEDINGUNGEN)
NO_BINARY_CHECK = true
TRUNCATE = 1000000
category = Custom
disabled = false
pulldown_type = true
SHOULD_LINEMERGE = false

Anybody encountered this weird issue?

Tags (1)
0 Karma
1 Solution

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

schomar
New Member

There was no timestamp defined in the source type,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...