I am having a random issue where it seems characters are present in a field which cannot be seen. If you look in the results below, even though the results appear to match each other, Splunk does se...
See more...
I am having a random issue where it seems characters are present in a field which cannot be seen. If you look in the results below, even though the results appear to match each other, Splunk does see these as 2 distinct values. If I download and open the results, one of the two names has characters in it that are not seen when looking at the results in the Search App. If I open the file in my text editor, one of the two names is in quotes, if I open the file in Excel, one of the two names is preceded by ‚Äã. It feels like a problem with the underlying lookup files (.csv), however this problem is not consistent, only a very small percentage of results has this incorrect format (<.005%). Trying to use regex or replace to remove non-alphanumeric values in a field does not seem to work, I am at a loss with it. Any idea how to remove "non-visible" characters or correct this formatting?