Splunk server is receiving garbage data from the ProxySG Access Logs.

book

Article ID: 168782

calendar_today

Updated On:

Products

Advanced Secure Gateway Software - ASG ProxySG Software - SGOS

Issue/Introduction

When sending data to a Splunk server for data collection, the proxy appears to be sending garbage data instead of log files.

Example:
\x8B#\xC4\xF6U\x00ݛmkG\xC7\xDF\xFAA!)\xF5i\x9FwϦ/\x9A\xD4MC ;Tn\xFD2\x9C\xE5\xB3%,\xDD\xDD\xDB\xFD\xF4\x9D=\xDFJj\xA2\x82\x94\x8C\xBA\x83 \x81ĉt\xFA\xED\xC3\xCCf\xFE\x92\\x98\x9E¬̈́<4\xF6\x90
&<\xFC\x85g"\x93<s\x8Et\xBFN_\x8D\x8E\xFF\xF8\xEB\xF8W6xu \xD7L\xAB\xB2i\x86\xC7㺪\xE7\x8FG\xBFMg%\xB5\xF5\xA2\xB8.\x87\xA3I\xB1 \x98V\xD7\xC6\xD9ٟ''\xC7\xEF\xE1%w\xD5MU\xDFW\xF0.M3c\xB3b|ӴuUf\xF7E;\x9E\\xD6ٸ\x9E3\xADU\xF7$\xE1d& <\g"gF)\xE6|
?\xAF\xE0 \xDD\x98L\xAF'\xEC\xC7\xBF\xF8\x8BO5\xF8\xFE;\xF9\x9BfҺ%\x9B\xE1\xF8l\x93\xC56T\x9AۜY'\xB1\xB0\xB4\[email protected]% *\xA9\xB1\xA8D\xF7;9Vw

Cause

The Access Logging Upload Client 'Save the log file as:' Transmission Parameters are configured to upload the log as a gzip file instead of a text file.

Resolution

On the proxy, go to Configuration tab > Access Logging > Logs > Upload Client tab

Select the affected Log file from the drop·down

Select text file and Apply.