Getting Data In

Splunk Encoding

germ18413
New Member

Hi Splunk Guys,

I have an issue with some log encoding in french

In the log i have this :
Connexion à la base Master...

In splunk i have this
Connexion \xE0 la base Master : OK

i have change the encoding charset in my props.conf

[toto:log]
DATETIME_CONFIG = CURRENT
CHARSET=ISO-8859-1
LINE_BREAKER=([\r\n]+)
SHOULD_LINEMERGE=true
disabled=false

But the encoding still bad in my search

already tried with CHARSET=LATIN1
But same issue

Many thanks 🙂

Tags (1)
0 Karma

ddrillic
Ultra Champion

It's interesting if Splunk supports Latin1. It was the prevalent encoding a couple of decades ago ; -)

The following French users : how to get "é" instead of "/xE9"

Says -

 [default]
 CHARSET = latin-1
0 Karma