<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PingOne/PingIdentity log subscription ingestion - logs unreadable in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/PingOne-PingIdentity-log-subscription-ingestion-logs-unreadable/m-p/392397#M70100</link>
    <description>&lt;P&gt;Turns out my load balancer was re-encrypting the logs before pushing them to my forwarders. Disabling the encryption resolved the issue.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Aug 2018 19:40:20 GMT</pubDate>
    <dc:creator>kschiemo</dc:creator>
    <dc:date>2018-08-22T19:40:20Z</dc:date>
    <item>
      <title>PingOne/PingIdentity log subscription ingestion - logs unreadable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/PingOne-PingIdentity-log-subscription-ingestion-logs-unreadable/m-p/392396#M70099</link>
      <description>&lt;P&gt;I am sending logs from PingOne to my heavy forwarder. The logs are being streamed to the forwarder via TCP. The logs are configured to be in the 'SPLUNK_AUDIT' format. The logs showing up in splunk are not readable. &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/254631-2018-08-03-15-29-33-search-splunk-665.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Here is the relevant documentation from Ping Identity regarding this format:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Format&lt;/STRONG&gt;  (Required) -- The subscription format to use. This can be one of the following:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;AUDIT&lt;/EM&gt; - The PingOne audit event format (JSON).&lt;BR /&gt;
&lt;EM&gt;SPLUNK_AUDIT&lt;/EM&gt; - The PingOne audit event format wrapped with the fields needed for processing by Splunk (JSON).&lt;/P&gt;

&lt;P&gt;Here are my inputs.conf and props.conf configurations.&lt;/P&gt;

&lt;P&gt;-- inputs.conf --&lt;BR /&gt;
[tcp://:10000]&lt;BR /&gt;
index = main&lt;BR /&gt;
sourcetype = pingid&lt;/P&gt;

&lt;P&gt;-- props.conf --&lt;BR /&gt;
[pingid]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
TIME_PREFIX="timestamp":&lt;BR /&gt;
TIME_FORMAT=%s&lt;BR /&gt;
KV_MODE = false&lt;BR /&gt;
INDEXED_EXTRACTIONS = json&lt;/P&gt;

&lt;P&gt;Does anyone have any ideas on how I can adjust my ingestion settings so that these logs are readable? Or is this indicative of a problem with how I've set up the logs to be sent from PingOne (it is a pretty straightforward process so I am doubtful of this personally). I am expecting to see pretty generic JSON data coming through. I have played around with the JSON parsing options in splunk (KV_MODE = json), but I don't believe that this is a JSON parsing issue. I have also experimented with specifying differing CHARSETs in my props.conf, thinking that perhaps the logs are coming in a non-UTF8 format, but also to no avail.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/PingOne-PingIdentity-log-subscription-ingestion-logs-unreadable/m-p/392396#M70099</guid>
      <dc:creator>kschiemo</dc:creator>
      <dc:date>2020-09-29T20:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: PingOne/PingIdentity log subscription ingestion - logs unreadable</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/PingOne-PingIdentity-log-subscription-ingestion-logs-unreadable/m-p/392397#M70100</link>
      <description>&lt;P&gt;Turns out my load balancer was re-encrypting the logs before pushing them to my forwarders. Disabling the encryption resolved the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 19:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/PingOne-PingIdentity-log-subscription-ingestion-logs-unreadable/m-p/392397#M70100</guid>
      <dc:creator>kschiemo</dc:creator>
      <dc:date>2018-08-22T19:40:20Z</dc:date>
    </item>
  </channel>
</rss>

