Based on my experiments it seems Splunk expects the encoding to be UTF-8. I sent strings with German, Greek and Russing special characters and they were displayed correctly in the web UI.
Example:

I also tried UCS-2, but that did not work out too well:

Based on my experiments it seems Splunk expects the encoding to be UTF-8. I sent strings with German, Greek and Russing special characters and they were displayed correctly in the web UI.
Example:

I also tried UCS-2, but that did not work out too well:
