Hi, I write this question in English to allow evry users to access it.
I get logs from Windows application installed on a french Windows system.
When Splunk indexes these logs, french caracters are displayed with there code not the caracter itself.
I Found that it should be du to the character encoding utf-8 instead of latin-1.
Does somedy knows where I can change this encoding and what should be the result over my splunk install ?
Thanks.
Edit $SPLUNK_HOME/etc/system/local/props.conf and add the following stanza:
[default]
CHARSET = latin-1
If you have a specific application, perform the same modification under $SPLUNK_HOME/etc/apps/<APP_NAME>/local/props.conf
Then restart Splunk.