Splunk Search

Icelandic unicode character - "Interesting fields" showing no result

sjova
Engager

Hi,

I'm writing json NLog files from Visual Studio into Splunk (with NLog WebService target).

In my Splunk search results, if I filter my search with "Add to search" it works (because of "spath" so it seems, that gets added automatically):
Splunk search: ...| spath Message | search Message="Villa við að...." | sort -Date
(the raw json data: "Message": "Villa vi\u00f0 a\u00f0 )

\u00f0 is an Icelandic unicode character:
https://www.fileformat.info/info/unicode/char/00f0/index.htm

However, if I click the "Message" property value on the left in "Interesting fields", I get "No results found". The splunk search doesn't add the "spath" to the search:
Splunk search: ...Message="Villa við að stofna liabilityevaluationclaimholders." | sort -Date

One solution would be to automacially add "spath" whenever somebody clicks a property value in "Interesting fields". Is that possible (just like is done when you add the property value as a filter in the search results)?

Or is there a more obvious solution (not requiring "spath" in the search)?

Thanks a lot,
Gunnar

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...