Strange Characters in the Cisco CGNAT LOG

I am receiving interrogated characters in logs sent from Cisco ASR to Graylog, what am I doing wrong?

timestamp source
2021-03-22 00:32:45 -03:00 45.226.139.17
4z\�`X��,�ea���C������3���@@ea���C��<a ��3�����C�����3��ea�����C����_<a ��3�����@@eea�����C����_<a ��3����ea�����C����_<a

Good morning, I have seen that if the source is trying encrypt and the input is not setup for TLS. Thank you, Zach.

Goog morning,

I need configure on Graylog server or Router ? Where I see the TLS configuration ?

Best Regards,
Maurício.

In my case the source was sending TLS to a non-TLS Input. I disabled TLS at the source, not in Graylog.

@Campjones

How is your input configured for the Cisco ASA?
What verion of graylog do you have?

Suggestion:
You can try using a Syslog UDP input with your Cisco ASR appliances or, if that fails, a Raw/Plaintext UDP input.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.