Monitoring Splunk

UTF8Processor warning message

ollie920049
Path Finder

Hi there,

I have CHARSET = UTF-16LE enforced in props.conf for all universal forwarders.

For UniForwarder -> Indexer this all works correctly. However, for UniForwarder -> HeavyForwareder -> Indexer this causes an WARN log entry for each processed event on the heavy forwarder:

12-04-2014 15:27:48.026 +0000 WARN UTF8Processor - Using charset UTF-8, as the monitor is believed over the raw text which may be UTF-16LE

Any ideas what I can do to fix this? It's currently being indexed correctly, but generating 1000's of WARN's a minute.

Thanks in advance

Tags (2)

gavsdavs_GR
Path Finder

Your HF is parsing, whatever it is you have set up for the sourcetype on the indexer needs to be on the HF too.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...