Splunk Search

Icelandic unicode character - "Interesting fields" showing no result

sjova
Engager

Hi,

I'm writing json NLog files from Visual Studio into Splunk (with NLog WebService target).

In my Splunk search results, if I filter my search with "Add to search" it works (because of "spath" so it seems, that gets added automatically):
Splunk search: ...| spath Message | search Message="Villa við að...." | sort -Date
(the raw json data: "Message": "Villa vi\u00f0 a\u00f0 )

\u00f0 is an Icelandic unicode character:
https://www.fileformat.info/info/unicode/char/00f0/index.htm

However, if I click the "Message" property value on the left in "Interesting fields", I get "No results found". The splunk search doesn't add the "spath" to the search:
Splunk search: ...Message="Villa við að stofna liabilityevaluationclaimholders." | sort -Date

One solution would be to automacially add "spath" whenever somebody clicks a property value in "Interesting fields". Is that possible (just like is done when you add the property value as a filter in the search results)?

Or is there a more obvious solution (not requiring "spath" in the search)?

Thanks a lot,
Gunnar

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...