<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get anything other than SYSLOG events to come into Splunk from F5 in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392355#M47890</link>
    <description>&lt;P&gt;I am facing the same issue . We have create a rule using F5 iapp .But only the syslog events are ingested . &lt;/P&gt;</description>
    <pubDate>Sun, 06 Jan 2019 11:32:15 GMT</pubDate>
    <dc:creator>Nadhiyaa</dc:creator>
    <dc:date>2019-01-06T11:32:15Z</dc:date>
    <item>
      <title>Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392354#M47889</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Currently running F5 13.1.0, and Splunk Enterprise 7.1.2, i'm utilizing F5 Network s- Analytics (New) v1.0 App, and F5's Analytics Template v3.7.1.&lt;/P&gt;

&lt;P&gt;When I enable &lt;STRONG&gt;Local System Logging (syslog)&lt;/STRONG&gt; I get a slew of Syslog events from F5, all other events are not showing up. The only error I receive in &lt;STRONG&gt;/var/log/ltm&lt;/STRONG&gt; is the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Jan  4 04:00:30 f5-n1 notice mcpd[5856]: 0107167d:5: Data publisher not found or not implemented when processing request (unknown request), tag (2901).
Jan  4 04:00:35 f5-n1 err scriptd[13853]: 014f0013:3: Script (/Common/Splunk-send_stats) generated this Tcl error: (script did not successfully complete: (01020036:3: The requested RADIUS Server (/Common/Splunk.app) was not found.     while executing "tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth"     invoked from within "lindex [tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth] 0"     invoked from within "set obj [lindex [tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth] 0]" line:41))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I know this might be a F5 issue but after going over the Deployment Guide, its pretty self explanatory.... I do have syslog events going into my F5 Index (f5-bigip) but the dashboard never shows any results, and my only events are syslog. I would like to be able to get Member Pools, ASM, GTM and LTM information into this tool if its feasible.&lt;/P&gt;

&lt;P&gt;Any help would be much appreciated, thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 21:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392354#M47889</guid>
      <dc:creator>evolutionxtinct</dc:creator>
      <dc:date>2019-01-04T21:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392355#M47890</link>
      <description>&lt;P&gt;I am facing the same issue . We have create a rule using F5 iapp .But only the syslog events are ingested . &lt;/P&gt;</description>
      <pubDate>Sun, 06 Jan 2019 11:32:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392355#M47890</guid>
      <dc:creator>Nadhiyaa</dc:creator>
      <dc:date>2019-01-06T11:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392356#M47891</link>
      <description>&lt;P&gt;@Nadhiyaa &lt;/P&gt;

&lt;P&gt;If you run a TCPDUMP from the interface and you disable hat syslog do you also see no traffic generated?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jan 2019 14:18:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392356#M47891</guid>
      <dc:creator>evolutionxtinct</dc:creator>
      <dc:date>2019-01-06T14:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392357#M47892</link>
      <description>&lt;P&gt;@Nadhiyaa&lt;/P&gt;

&lt;P&gt;Wanted to give you an update, after working w/ ANM they had a engineer that worked w/ F5 development, the issue is with the &lt;STRONG&gt;F5 Analytics iApp v3.7.1&lt;/STRONG&gt;, you will need to use &lt;STRONG&gt;v3.7.2RC5&lt;/STRONG&gt; when you download the bundle from F5, under analytics folder should be a Release Canidate folder, and it has this .tmpl file in there. &lt;/P&gt;

&lt;P&gt;When I put this in place, I got a SLEW of data, but i'm finding that the Splunk F5 app dashboard panel, are using a search query of "UNDEFINED" so now i'm facing data not collecting in panels due to this.&lt;/P&gt;

&lt;P&gt;Hope this helps you, good luck!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392357#M47892</guid>
      <dc:creator>evolutionxtinct</dc:creator>
      <dc:date>2019-01-15T16:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392358#M47893</link>
      <description>&lt;P&gt;One thing F5 also suggested, is having the F5 Analytics profile applied to your Virtual Servers, that may also be another reason why its now working - the iApp RC5 is still the fix, just this is an additional thing to do.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392358#M47893</guid>
      <dc:creator>evolutionxtinct</dc:creator>
      <dc:date>2019-01-15T16:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392359#M47894</link>
      <description>&lt;P&gt;Thanks for posting this, I'm struggling with this as well. I initially set it up in our DEV splunk and even though the dashboards were not populating I was still getting useful logs like bigip.logs which includes application info, vips, etc... A week ago or so, I deployed the F5 app on our PRD  HF and SH and now I only get syslog/snmp data. I tried moving it back to DEV splunk but it looks like the iApp just stopped parsing and forwarding the data properly. I will try the RC5 like you mentioned and see if it helps. If you have any additional info/updates, please share.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 18:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392359#M47894</guid>
      <dc:creator>pzharyuk</dc:creator>
      <dc:date>2019-01-18T18:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get anything other than SYSLOG events to come into Splunk from F5</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392360#M47895</link>
      <description>&lt;P&gt;@pzharyuk : Hey man , did u get this to work ..?? How was it resolved ..?? Kindly share ..!!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 02:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Unable-to-get-anything-other-than-SYSLOG-events-to-come-into/m-p/392360#M47895</guid>
      <dc:creator>millinkan</dc:creator>
      <dc:date>2020-04-06T02:26:01Z</dc:date>
    </item>
  </channel>
</rss>

