Splunk Search

Splunk Encoding Issue with Not Sign (¬)

bveltre
New Member

Hello,

I am trying to send some records to Splunk that are incorrectly getting written.

This is what the message looks like in Splunk: TERMID=\xACAAB
This is what the message should look like: TERMID=¬AAB

I cant seem to find a character set encoding that correctly displays the 'not' sign (¬). I believe that this is something that could be fixed by updating the props.conf file and changing the character set encoding.

I tried using the default UTF-8 encoding and was recommended to use LATIN1, but did not have any luck with either.

In Hex, this value is x’5F’

Any help or recommendations on how to properly resolve this would be greatly appreciated.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...