<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic F5 Source Type Indexing in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/F5-Source-Type-Indexing/m-p/504539#M1981</link>
    <description>&lt;P&gt;Hi, I have just begun ingesting F5 logs, I am not using the modular inputs component at present and am only seeing ASM logs via syslog. Logs are being sent to a syslog server and file monitoring is set to pull into splunk indexer. But when searching logs the logs dont seem to be separating expected "dur&lt;SPAN&gt;ing index time, the add-on separates the data into more specific source types."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have an inputs.conf file on the rsyslog server distributed by a universal forwarder.&lt;/P&gt;&lt;P&gt;[monitor:..........]&lt;/P&gt;&lt;P&gt;disabled = 0&lt;/P&gt;&lt;P&gt;host_segment = 5&lt;/P&gt;&lt;P&gt;index=f5&lt;/P&gt;&lt;P&gt;sourcetype= f5:bigip:syslog&lt;/P&gt;&lt;P&gt;I have removed the inputs from the indexer and have added the add-on to the search head as well. Confused as to why the logs are separating. Hoping someone can help&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2020 06:24:34 GMT</pubDate>
    <dc:creator>heidihart</dc:creator>
    <dc:date>2020-06-16T06:24:34Z</dc:date>
    <item>
      <title>F5 Source Type Indexing</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/F5-Source-Type-Indexing/m-p/504539#M1981</link>
      <description>&lt;P&gt;Hi, I have just begun ingesting F5 logs, I am not using the modular inputs component at present and am only seeing ASM logs via syslog. Logs are being sent to a syslog server and file monitoring is set to pull into splunk indexer. But when searching logs the logs dont seem to be separating expected "dur&lt;SPAN&gt;ing index time, the add-on separates the data into more specific source types."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have an inputs.conf file on the rsyslog server distributed by a universal forwarder.&lt;/P&gt;&lt;P&gt;[monitor:..........]&lt;/P&gt;&lt;P&gt;disabled = 0&lt;/P&gt;&lt;P&gt;host_segment = 5&lt;/P&gt;&lt;P&gt;index=f5&lt;/P&gt;&lt;P&gt;sourcetype= f5:bigip:syslog&lt;/P&gt;&lt;P&gt;I have removed the inputs from the indexer and have added the add-on to the search head as well. Confused as to why the logs are separating. Hoping someone can help&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 06:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/F5-Source-Type-Indexing/m-p/504539#M1981</guid>
      <dc:creator>heidihart</dc:creator>
      <dc:date>2020-06-16T06:24:34Z</dc:date>
    </item>
  </channel>
</rss>

