Getting Data In

AWS VPC Flow logs getting ingested non-human readable format

sathiyasun
Explorer

Standard format of data ingestion with default setup sending data via HEC token, Data getting ingested non-human readable format. Tried creating a new token and sourcetype but still no luck. Please advise what else should we do differently to get proper format.

 

12/3/24
9:21:58.000 AM
 
P}\x00\x00\x8B\x00\x00\x00\x00\x00\x00\xFFE\x90\xDDn\x9B@\x84_eun\xF6\xA2v}\xF6\xD8;lo$W\xDEM\xD5
 12/3/24
9:21:58.000 AM
 
\xB9\xB7\xE6\xA0sV\xBA\xA0\x85\xFF~H\xA4[\xB31D\xE7aI\xA8\xFDe\xD7˄~\xB5MM\xE6>\xDCAIh_\xF5ç\xE0\xCCa\x97f\xC9V\xE7XJ o]\xE2\xEE\xED{3N\xC0e\xBA\xD6y\K\xA3P\xC8&\x97\xB16\xDDg\x93Ħ\xA0C\xC5\xE3\x80~\x82\xDD\xED\xAD\xD39%\xA1\xEDu\xCE\x9F35\xC7y\xF0IN\xD6\xF6?\xF8\xE3\xE0\xEC~\xB7\x9Cv\x9D\x92 \x91\xC2k\xF9\xFANO
 12/3/24
9:21:58.000 AM
 
Y7'BaRsԈd\xBA\x88|\xC1i.\xFC\xD6dwG4\xA1<iK\xF7ѹ* ]\xED\xB3̬-\xFC\xF4\xF7eb
 12/3/24
9:21:58.000 AM
 
.e #r.\xA4P\x9C\xB1(\x8A# \xA98\x86(e\xAC\x82\xB8B\x94\xA1`(ac{i\x86\xB1\xBA\A3%\xD3r\x888\xFB\xF73\xD0\xE0n
 12/3/24
9:21:58.000 AM
 
"
 12/3/24
9:21:58.000 AM
 
3néo\xAFc\xDB\xF9o\xEDyl\xFAto\xED\xF3\xB1\x9B\xFFn}3\xB4\x94o$\xF3\xA7\xF1\xE3dx\x81\xB6
 12/3/24
9:21:58.000 AM
 
\x98`_\xAB[
 12/3/24
9:21:58.000 AM
 
&9"!b\xA3
 12/3/24
9:21:58.000 AM
 
\xD5Ӱ\xE8\xEBa\xD1\xFAa\xAC\xFC\xA9Yt}u:7\xF5â\xBA\xD5\xED\xF8\xEE\xB6c\xDFT\xD0\xF0\xF3`6κc\xD7WG19r\xC98
 12/3/24
9:21:58.000 AM
 
\xAA\x80+\x84\xC8b\x98\xC1\xB9{\xDC\xF4\xDD\xED
Labels (2)
0 Karma

rishabhshah
Path Finder

Have you installed AWS TA and Splunk Add-on for Amazon Kinesis Firehose for parsing? Document

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...