We are attempting to onboard logs from Aruba ClearPass to Splunk Cloud via Splunk SC4S. While logs are successfully arriving at Splunk SC4S from the Aruba ClearPass server, they are not reaching Splunk Cloud.
Upon closer inspection of the logs arriving from Aruba ClearPass to Splunk SC4S, we observed that the logs contain null byte codes "0x0...". We suspect that the presence of these null bytes might be preventing the logs from being indexed in Splunk Cloud.
The logs being forwarded are in CEF format. Could this be a parsing issue?