Getting Data In

AWS VPC Flow logs getting ingested non-human readable format

sathiyasun
Explorer

Standard format of data ingestion with default setup sending data via HEC token, Data getting ingested non-human readable format. Tried creating a new token and sourcetype but still no luck. Please advise what else should we do differently to get proper format.

 

12/3/24
9:21:58.000 AM
 
P}\x00\x00\x8B\x00\x00\x00\x00\x00\x00\xFFE\x90\xDDn\x9B@\x84_eun\xF6\xA2v}\xF6\xD8;lo$W\xDEM\xD5
 12/3/24
9:21:58.000 AM
 
\xB9\xB7\xE6\xA0sV\xBA\xA0\x85\xFF~H\xA4[\xB31D\xE7aI\xA8\xFDe\xD7˄~\xB5MM\xE6>\xDCAIh_\xF5ç\xE0\xCCa\x97f\xC9V\xE7XJ o]\xE2\xEE\xED{3N\xC0e\xBA\xD6y\K\xA3P\xC8&\x97\xB16\xDDg\x93Ħ\xA0C\xC5\xE3\x80~\x82\xDD\xED\xAD\xD39%\xA1\xEDu\xCE\x9F35\xC7y\xF0IN\xD6\xF6?\xF8\xE3\xE0\xEC~\xB7\x9Cv\x9D\x92 \x91\xC2k\xF9\xFANO
 12/3/24
9:21:58.000 AM
 
Y7'BaRsԈd\xBA\x88|\xC1i.\xFC\xD6dwG4\xA1<iK\xF7ѹ* ]\xED\xB3̬-\xFC\xF4\xF7eb
 12/3/24
9:21:58.000 AM
 
.e #r.\xA4P\x9C\xB1(\x8A# \xA98\x86(e\xAC\x82\xB8B\x94\xA1`(ac{i\x86\xB1\xBA\A3%\xD3r\x888\xFB\xF73\xD0\xE0n
 12/3/24
9:21:58.000 AM
 
"
 12/3/24
9:21:58.000 AM
 
3néo\xAFc\xDB\xF9o\xEDyl\xFAto\xED\xF3\xB1\x9B\xFFn}3\xB4\x94o$\xF3\xA7\xF1\xE3dx\x81\xB6
 12/3/24
9:21:58.000 AM
 
\x98`_\xAB[
 12/3/24
9:21:58.000 AM
 
&9"!b\xA3
 12/3/24
9:21:58.000 AM
 
\xD5Ӱ\xE8\xEBa\xD1\xFAa\xAC\xFC\xA9Yt}u:7\xF5â\xBA\xD5\xED\xF8\xEE\xB6c\xDFT\xD0\xF0\xF3`6κc\xD7WG19r\xC98
 12/3/24
9:21:58.000 AM
 
\xAA\x80+\x84\xC8b\x98\xC1\xB9{\xDC\xF4\xDD\xED
Labels (2)
0 Karma

rishabhshah
Path Finder

Have you installed AWS TA and Splunk Add-on for Amazon Kinesis Firehose for parsing? Document

0 Karma
Get Updates on the Splunk Community!

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...