Splunk server is receiving garbage data from the Edge SWG Access Logs.
search cancel

Splunk server is receiving garbage data from the Edge SWG Access Logs.

book

Article ID: 168782

calendar_today

Updated On:

Products

Advanced Secure Gateway Software - ASG ProxySG Software - SGOS

Issue/Introduction

When sending data to a Splunk server for data collection, the proxy appears to be sending garbage data instead of log files.


Cause

The Access Logging Upload Client 'Save the log file as:' Transmission Parameters are configured to upload the log as a gzip file instead of a text file.

Resolution

On the EdgeSWG SGAC console, go to Administration tab > Access Logging > Click on the affected Log file (e.g main) under Logs > Transmission Parameters 

Select "Text File" beside the label "Save The Log File As:" and click Apply.