send log from Splunk Universal Forwarder to Nagios Log server

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Post Reply
halimm
Posts: 1
Joined: Tue Apr 02, 2024 3:04 am

send log from Splunk Universal Forwarder to Nagios Log server

Post by halimm »

Hi all,
Currently we're doing testing to send logs from Splunk Universal Forwarder to Nagios Log Server. We've installed Splunk UF in a window machine so that event from windows be sent to Splunk UF and then afterwards sent to Nagios Log Server. Received the connection in Nagios Log Server but the log itself is not readable. Received the log like below

"\u0016\u0003\u0001\u0000\x8C\u0001\u0000\u0000\x88\u0003\u0003\x92>\x...."

Anyone ever tried this setup and able to received readble log ?

Your kind feedback is very much appreciated.
jsimon
Posts: 105
Joined: Wed Aug 23, 2023 11:27 am

Re: send log from Splunk Universal Forwarder to Nagios Log server

Post by jsimon »

Hi @halimm,

A bunch of the individual unicode values in that string do not translate to human readable characters, it looks like a bunch of header characters. I believe you'll need to configure Splunk or add some sort of filter to preprocess the output before it gets into Logstash to remove this sort of value.
User avatar
jmichaelson
Posts: 118
Joined: Wed Aug 23, 2023 1:02 pm

Re: send log from Splunk Universal Forwarder to Nagios Log server

Post by jmichaelson »

Please let us know if you have any other questions or concerns.

-Jason
Post Reply