Splunk Enterprise Security

Logs are coming in Hex

xian
New Member

We are testing a study on routing logs from an e-mail security product we have used to the SIEM environment. In this context, we carried out studies using free or community versions of different SIEM products.

The logs transmitted to Splunk were sent encrypted with TLS as they were transmitted to other products. However, the logs we see on Splunk cannot be decrypted and come in the below.

Example output: \x00 \x00 \xFC m\xDF qs\x81\xF2^8g&&\xB3B\xDF\xF9\xD5

I checked the config files in Splunk and it already supported TLS. 

How can I fix that issue? 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...