Splunk Search

File upload with user defined charset does not recognized German umlaute

schomar
New Member

We are trying to upload a text file with German text, but the German umlaute are not recognized

Manual file upload (only works on second attempts)

Procedure:
Add data
1. Select Source (file) -> next
2. Set Source Type
(custom)
- line break is working
- charset MS-ANSI German umlaute are not recognized -> next
3. Input settings
...

However, still within the wizard ...
... when we select in the wizard step 3. Input settings back and next ...
... the charset is recognized and German umlaute is recognized!

automatic file monitoring (does not work either)

Monitoring a folder for input does not recognize the charset MS-ANSI and German umlaute at all

Source type used

CHARSET = MS-ANSI
LINE_BREAKER = (ENDG.*LTIGE BEDINGUNGEN)
NO_BINARY_CHECK = true
TRUNCATE = 1000000
category = Custom
disabled = false
pulldown_type = true
SHOULD_LINEMERGE = false

Anybody encountered this weird issue?

Tags (1)
0 Karma
1 Solution

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

When you create a custom sourcetype via the web UI, it is not automatically distributed (learned this the hard way).
Though it is written to disk, you have to distribute it manually, or via deployment server.

Otherwise, what appears correct in the data preview, is not what you get from ingestion/search.

https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Distributesourcetypeconfigurations

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

schomar
New Member

There was no timestamp defined in the source type,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...