Splunk supports the internationalization and localization of strings within the product. Use Splunk's localization tools to:
- Set language/locale specific alternatives for static resources such as images, CSS, other media.
- Create new languages or locales.
- Format times, dates and other numerical strings.
When you log in to Splunk, Splunk uses the language that your browser is set to. If you'd want to switch languages, change your browser settings.
Splunk detects locale strings. A locale string contains two components: a language specifier and a localization specifier. This is usually presented as two lowercase letters and two uppercase letters linked by an underscore. For example,
en_US means US English while
en_GB means British English.
When looking for a suitable translation, Splunk first tries to find an exact match for the whole locale, but falls back to just the language specifier if the entire setting is not available. For example, translations for
fr answer to requests for
fr_FR (French, Canada and France respectively). The user's locale also affects the formatting of dates, times, numbers, and other localized settings. Different countries have differing standards on how to format these entities.
Splunk uses the gettext internationalization and localization system. When using gettext, you typically use an editor to create, generate, and edit the files used to localize strings in an application. Splunk recommends Poedit, a free, open source editor for localization.
To translate Splunk, follow these directions:
1. Create a directory for the locale. For example, to create the fictional locale
mz, create the following directory:
2. Load the following
messages.pot file into your PO editor.
3. Use the PO editor to translate any strings you want to localize. Save the file as
messages.po in the directory you created in step 2. The PO editor also saves a
messages.mo file, which is the machine readable version of the PO file.
4. Restart Splunk. There are no other configuration files to edit. Splunk detects the new language files when it restarts.
Splunk stores localization information at the following location:
messages.pot: Holds the strings to translate. Use a PO editor to edit these files.
<locale_string>: The directory containing localization files for the locale specified by <locale_string> (for example,
<locale_string>/LC_MESSAGES/messages.po: Contains the source strings specified for localization in
messages.pot. Using a PO editor, provide the translations for these strings.
<locale_string>/LC_MESSAGES/messages.mo: A machine readable version of
messages.pothat Splunk uses to find translated strings. The PO editor creates this for you when it creates the
Localize dates and numbers
You can format numbers and dates to the standards of a locale without having to translate any text. For this scenario, copy the contents of the
en_US directory to the target locale directory.
For example, to enable localization of numbers and dates for the
it_IT locale (Italian – Italy), copy the contents of the following directory:
and place them here:
You can also use gettext to translate apps. However, most apps must be translated in their own locale subdirectory. Apps that ship with Splunk are automatically extracted and their text included in Splunk's core
messages.pot file. There's no need to handle them separately.
To extract the strings from an installed application, ready to be translated in a PO editor, run the following command from Splunk's command line:
splunk extract i18n -app <appname>
This creates a locale/ subdirectory in the app's root directory and populates it with a
messages.pot file. Then, follow the steps above to translate the strings within the app. When using views from a different app, the new
messages.pot file contains the strings for these views.
Splunk stores static resources such as images, CSS files, and other media as subdirectories at the following location:
When serving these resources, Splunk checks to see whether a locale-specific version of the resource is available before falling back to the default resource. For example, if your locale is set to
fr_FR, Splunk searches for the logo image file in the following order:
Splunk follows the same path to load HTML templates (including any views) that define each page in the UI. This can be useful for languages that require a modified layout that CSS alone can't accommodate (right to left text for example).
Plot search results on a map
This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7