All Apps and Add-ons

Is there a way to automatically decode Cisco Ironport UTF-8?

ravikirantaleka
Explorer

Hello,

I am importing Cisco Ironport data into Splunk, field "subject" contains UTF-8 encoded data with jumbled characters. Is there a way to automatically decode the subject to a string format? Now, I am using Powershell and CyberChef application to decode manually.

Kindly let me know how to solve this issue.

Regards,

RK

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @ravikirantaleka,

which TA are you using to parse the Cisco Ironport logs?

Did you tried with Splunk Add-On for Cisco ESA (https://splunkbase.splunk.com/app/1761/)?

It should contain all the configuration to parse the Cisco Ironport logs.

Ciao.

Giuseppe

View solution in original post

ravikirantaleka
Explorer

Hi @gcusello,

I am using ESA TA that you mentioned, the normal string is parsed well. However, URL, Chinese, and not English characters are still displayed in base64 format. Now, I am wondering if Cisco Ironport has to have some configuration at their end to decode the characters before sending data into Splunk.

What do you think?

//RK

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ravikirantaleka,

it shouldn't have, buit i don't know your local configurations.

in this case the only whay is to try with different charsets.

Ciao.

Giuseppe

0 Karma

ravikirantaleka
Explorer

Hi @gcusello,

Looks like it's a known bug at Cisco Ironport.

Cisco Bug: CSCun16129 - Translate subjects from base64 to human-readable format for export

Thank you for your input

//RK

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ravikirantaleka,

see next time!

Please accept one answer for the other people of Community

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ravikirantaleka,

which TA are you using to parse the Cisco Ironport logs?

Did you tried with Splunk Add-On for Cisco ESA (https://splunkbase.splunk.com/app/1761/)?

It should contain all the configuration to parse the Cisco Ironport logs.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...