Splunk Search

Icelandic unicode character - "Interesting fields" showing no result

sjova
Engager

Hi,

I'm writing json NLog files from Visual Studio into Splunk (with NLog WebService target).

In my Splunk search results, if I filter my search with "Add to search" it works (because of "spath" so it seems, that gets added automatically):
Splunk search: ...| spath Message | search Message="Villa við að...." | sort -Date
(the raw json data: "Message": "Villa vi\u00f0 a\u00f0 )

\u00f0 is an Icelandic unicode character:
https://www.fileformat.info/info/unicode/char/00f0/index.htm

However, if I click the "Message" property value on the left in "Interesting fields", I get "No results found". The splunk search doesn't add the "spath" to the search:
Splunk search: ...Message="Villa við að stofna liabilityevaluationclaimholders." | sort -Date

One solution would be to automacially add "spath" whenever somebody clicks a property value in "Interesting fields". Is that possible (just like is done when you add the property value as a filter in the search results)?

Or is there a more obvious solution (not requiring "spath" in the search)?

Thanks a lot,
Gunnar

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...