Campjones
(MAURICIO DE SOUZA)
1
I am receiving interrogated characters in logs sent from Cisco ASR to Graylog, what am I doing wrong?
timestamp |
source |
2021-03-22 00:32:45 -03:00 |
45.226.139.17 |
4z\�`X��,�ea���C������3���@@ea���C��<a ��3�����C�����3��ea�����C����_<a ��3�����@@eea�����C����_<a ��3����ea�����C����_<a |
|
Good morning, I have seen that if the source is trying encrypt and the input is not setup for TLS. Thank you, Zach.
Campjones
(MAURICIO DE SOUZA)
3
Goog morning,
I need configure on Graylog server or Router ? Where I see the TLS configuration ?
Best Regards,
Maurício.
In my case the source was sending TLS to a non-TLS Input. I disabled TLS at the source, not in Graylog.
gsmith
(GSmith)
5
@Campjones
How is your input configured for the Cisco ASA?
What verion of graylog do you have?
Suggestion:
You can try using a Syslog UDP input with your Cisco ASR appliances or, if that fails, a Raw/Plaintext UDP input.
system
(system)
Closed
6
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.