<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting &amp;quot;[/Common/Splunk_DNS_REQUEST] error...undefined procedure:...&amp;quot; in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217362#M23599</link>
    <description>&lt;P&gt;Hi, what version of F5 are you on?&lt;/P&gt;</description>
    <pubDate>Sat, 27 Feb 2016 18:04:31 GMT</pubDate>
    <dc:creator>jcoates_splunk</dc:creator>
    <dc:date>2016-02-27T18:04:31Z</dc:date>
    <item>
      <title>Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217361#M23598</link>
      <description>&lt;P&gt;Unable to configure iRules in F5 as per the steps given in the Splunk docs: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_iRules_for_GTM"&gt;http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_iRules_for_GTM&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Error Message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01070151:3: Rule [/Common/Splunk_DNS_REQUEST] error: /Common/Splunk_DNS_REQUEST:7: error: [undefined procedure: whereami][whereami]
/Common/Splunk_DNS_REQUEST:9: error: [undefined procedure: whoami][whoami]
/Common/Splunk_DNS_REQUEST:10: error: [undefined procedure: wideip][wideip name]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 24 Feb 2016 08:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217361#M23598</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2016-02-24T08:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217362#M23599</link>
      <description>&lt;P&gt;Hi, what version of F5 are you on?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2016 18:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217362#M23599</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2016-02-27T18:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217363#M23600</link>
      <description>&lt;P&gt;We are seeing similar error. &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1080iFA8B021E95EF29AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 18:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217363#M23600</guid>
      <dc:creator>ppohar_splunk</dc:creator>
      <dc:date>2016-05-10T18:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217364#M23601</link>
      <description>&lt;P&gt;according to f5 documentation, whereami, whoami, wideip are all available in F5 version 10+&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 11:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217364#M23601</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-12T11:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217365#M23602</link>
      <description>&lt;P&gt;Client is on F5 version 11.5.2 HF1.0.169.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217365#M23602</guid>
      <dc:creator>ppohar_splunk</dc:creator>
      <dc:date>2016-05-12T13:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...undefined procedure:..."</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217366#M23603</link>
      <description>&lt;P&gt;I suggest you file a case with F5 support, they can help you determine why these functions are not available in the F5.  &lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 13:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/217366#M23603</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-05-12T13:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for F5 BIG-IP: How to configure iRules for F5 GTM? Getting "[/Common/Splunk_DNS_REQUEST] error...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/650051#M79434</link>
      <description>&lt;P&gt;I know this is an old thread, but wanted to provide some details as I ran into the same issue.&lt;/P&gt;&lt;P&gt;The Splunk docs provides separate iRules for DNS request logging and DNS response logging.&lt;/P&gt;&lt;P&gt;DNS request logging is configured in&amp;nbsp;&lt;STRONG&gt;DNS &amp;gt; GSLB &amp;gt; iRules&lt;/STRONG&gt;. They incorrectly state that you can apply this rule to your Listeners. You can only apply a GSLB iRule to wide IPs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS response logging is configured in &lt;STRONG&gt;DNS &amp;gt; Delivery &amp;gt; iRules&lt;/STRONG&gt;. I believe some older versions might list them in &lt;STRONG&gt;Local Traffic &amp;gt; iRules&lt;/STRONG&gt;. They incorrectly state you can apply the rule to wide IPs. You can only apply a LTM/Delivery iRule to Listeners.&lt;/P&gt;&lt;P&gt;While the logging does work assuming you apply the rules to the correct objects, the problem I had is ensuring that the request logging rule gets applied to all wide IPs. I want to do logging on the Listeners so I can set it and forget it. Rules configured within &lt;STRONG&gt;DNS &amp;gt; Delivery &amp;gt; iRules&amp;nbsp;&lt;/STRONG&gt;support both DNS_REQUEST and DNS_RESPONSE events, but they don't support the &lt;STRONG&gt;whereami&lt;/STRONG&gt;, &lt;STRONG&gt;whoami&lt;/STRONG&gt;, &lt;STRONG&gt;whereis&lt;/STRONG&gt;, and &lt;STRONG&gt;wideip name&lt;/STRONG&gt; commands. I simply remove the references to those commands and joined both the request and response rules into a single rule and applied it to my Listeners. I copied an example below.&lt;/P&gt;&lt;P&gt;when DNS_REQUEST {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set client_addr [IP::client_addr]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set dns_server_addr [IP::local_addr]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set question_name [DNS::question name]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set question_class [DNS::question class]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set question_type [DNS::question type]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set dns_len [DNS::len]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set hsl [HSL::open -proto UDP -pool Pool-syslog]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; HSL::send $hsl "&amp;lt;190&amp;gt;,f5_irule=Splunk-iRule-DNS_REQUEST,src_ip=$client_addr,dns_server_ip=$dns_server_addr,question_name=$question_name,question_class=$question_class,question_type=$question_type,dns_len=$dns_len"&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;when DNS_RESPONSE {&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set client_addr [IP::client_addr]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set dns_server_addr [IP::local_addr]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set question_name [DNS::question name]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set is_wideip [DNS::is_wideip [DNS::question name]]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set answer [join [DNS::answer] ;]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; set hsl [HSL::open -proto UDP -pool Pool-syslog]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; HSL::send $hsl "&amp;lt;190&amp;gt;,f5_irule=Splunk-iRule-DNS_RESPONSE,src_ip=$client_addr,dns_server_ip=$dns_server_addr,question_name=$question_name,is_wideip=$is_wideip,answer=\"$answer\""&lt;BR /&gt;}&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 11 Jul 2023 19:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-F5-BIG-IP-How-to-configure-iRules-for-F5-GTM/m-p/650051#M79434</guid>
      <dc:creator>rhombus00</dc:creator>
      <dc:date>2023-07-11T19:26:36Z</dc:date>
    </item>
  </channel>
</rss>

