<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic F5 iControl data collection issues [resolved] in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215920#M23409</link>
    <description>&lt;P&gt;A couple of things for people installing/configuring this app:&lt;/P&gt;

&lt;P&gt;These are over &amp;amp; above the instructions that come with the app:&lt;/P&gt;

&lt;P&gt;a) Ensure your &lt;EM&gt;$SPLUNK_HOME/etc/apps/xxx_all_indexes/local/indexes.conf&lt;/EM&gt; has been deployed to the HF.  The configuration screen for the Tasks will only allow you to select from a drop-down of locally configured indexes.  (Or manually update &lt;EM&gt;$SPLUNK_HOME/etc/SYSTEM/local/indexes.conf&lt;/EM&gt;)&lt;/P&gt;

&lt;P&gt;b) Ensure the user on the F5 has Admin &amp;amp; terminal permissions&lt;/P&gt;

&lt;P&gt;c) After you create the Server &amp;amp; create the Task to collect the data directly from the F5's ensure you edit the Task and re-direct it to an index other than 'main'&lt;/P&gt;

&lt;P&gt;d) BUG &amp;amp; Workaround: Observed with Splunk 6.2.6 - TA was deployed to an HF and once properly collecting data into '&amp;lt;your index here&amp;gt;' you can't search for results within a date/time range, you must search using 'All time'.  To correct this, on your HF (or wherever you are collecting the data) and update/create the following file:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update file: $SPLUNK_HOME/etc/apps/Splunk_TA_f5-bigip/local/props.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[f5_bigip:icontrol]
DATETIME_CONFIG = current

[f5:bigip:icontrol]
DATETIME_CONFIG = current
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;:  &lt;EM&gt;I did add the same option to all the other sourcetype stanzas as well, such as: [f5:bigip:gtm:dns:request:irule], [f5:bigip:system:systeminfo:icontrol], etc... I didn't test without them but I don't think you need them.  They are all listed in the props.conf in the default directory&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Going forward, all new events ingested will be searchable by time-range.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 07:47:15 GMT</pubDate>
    <dc:creator>sbarr0</dc:creator>
    <dc:date>2020-09-29T07:47:15Z</dc:date>
    <item>
      <title>F5 iControl data collection issues [resolved]</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215920#M23409</link>
      <description>&lt;P&gt;A couple of things for people installing/configuring this app:&lt;/P&gt;

&lt;P&gt;These are over &amp;amp; above the instructions that come with the app:&lt;/P&gt;

&lt;P&gt;a) Ensure your &lt;EM&gt;$SPLUNK_HOME/etc/apps/xxx_all_indexes/local/indexes.conf&lt;/EM&gt; has been deployed to the HF.  The configuration screen for the Tasks will only allow you to select from a drop-down of locally configured indexes.  (Or manually update &lt;EM&gt;$SPLUNK_HOME/etc/SYSTEM/local/indexes.conf&lt;/EM&gt;)&lt;/P&gt;

&lt;P&gt;b) Ensure the user on the F5 has Admin &amp;amp; terminal permissions&lt;/P&gt;

&lt;P&gt;c) After you create the Server &amp;amp; create the Task to collect the data directly from the F5's ensure you edit the Task and re-direct it to an index other than 'main'&lt;/P&gt;

&lt;P&gt;d) BUG &amp;amp; Workaround: Observed with Splunk 6.2.6 - TA was deployed to an HF and once properly collecting data into '&amp;lt;your index here&amp;gt;' you can't search for results within a date/time range, you must search using 'All time'.  To correct this, on your HF (or wherever you are collecting the data) and update/create the following file:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update file: $SPLUNK_HOME/etc/apps/Splunk_TA_f5-bigip/local/props.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[f5_bigip:icontrol]
DATETIME_CONFIG = current

[f5:bigip:icontrol]
DATETIME_CONFIG = current
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;:  &lt;EM&gt;I did add the same option to all the other sourcetype stanzas as well, such as: [f5:bigip:gtm:dns:request:irule], [f5:bigip:system:systeminfo:icontrol], etc... I didn't test without them but I don't think you need them.  They are all listed in the props.conf in the default directory&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Going forward, all new events ingested will be searchable by time-range.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215920#M23409</guid>
      <dc:creator>sbarr0</dc:creator>
      <dc:date>2020-09-29T07:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: F5 iControl data collection issues [resolved]</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215921#M23410</link>
      <description>&lt;P&gt;thank you sbarr0 -- I'm putting an answer on here for filtering purposes, but feel free to answer yourself to get the points &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2015 00:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215921#M23410</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-11-15T00:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: F5 iControl data collection issues [resolved]</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215922#M23411</link>
      <description>&lt;P&gt;This still affects the latest version of the F5 TA 2.4.0 as well as current should be all caps for the config for props should look like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[f5_bigip:icontrol]
 DATETIME_CONFIG = CURRENT

 [f5:bigip:icontrol]
 DATETIME_CONFIG = CURRENT
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 23 Mar 2016 13:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/F5-iControl-data-collection-issues-resolved/m-p/215922#M23411</guid>
      <dc:creator>bkoehler4070</dc:creator>
      <dc:date>2016-03-23T13:38:32Z</dc:date>
    </item>
  </channel>
</rss>

