Archive2
Highlighted

Logs after ingestion are not readable

Explorer

HI All ,

I am ingesting cloudwatch logs through s3->sns->sqs , on heavy forwarder using the aws add on using sqs based s3 as input type .
The logs in the bucket are in .gz format and when splunk ingest the logs and when i search for it , the logs are in not readable format .(all in special characters like 3÷/Í(2+½·ÔL3¥ÂïÅ^½}Ô ) .
Could you please guide of how i can solve this . i have ingested other logs in gz format and those can be read .

0 Karma
Reply