- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to configure character set encoding for Russian in Splunk?
templier
Communicator
11-11-2014
05:23 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

dimoobraznii
Path Finder
12-02-2014
03:06 AM
Hi!
I also met this problem with russian language.
And I fixed it.
The best option is to make input in preview mode. In advance tab just type:
CHARSET=CP1251
In addition, you can try with ISO-8859-5 and KOI8-R.
Just push "apply" and check result.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
templier
Communicator
12-02-2014
04:17 AM
Hi!
Tried to indicate in props.conf - did not help.
Using online change charset identified charset = koi-7 but indicate this parametr did not help too 😞
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

ppablo
Retired
11-11-2014
11:42 AM
Hi @templier
Have you looked at the documentation on configuring character set encoding in props.conf? http://docs.splunk.com/Documentation/Splunk/6.2.0/Data/Configurecharactersetencoding
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
templier
Communicator
12-02-2014
02:48 AM
Thank you for answer. Maybe it something that should be.
