<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311848#M2711</link>
    <description>&lt;P&gt;Hi micahkemp,  thanks for your effort on this, yes when we try to search with the above source type we are able to see the data in splunk console.   But its not parsing the data as expected. I am came to know that we need to place the  splunk Add-on for F5 BIG-IP in the Heavy forwarder instances to parse the data before indexing the data. &lt;/P&gt;

&lt;P&gt;But I have question now, since i am using the sourcetype = f5:bigip:syslog do I need to place entire content of the splunk Add-on in the HF server or we can place only the props/transforms related to the sourcetype=f5:bigip:syslog is enough. &lt;/P&gt;

&lt;P&gt;Kindly guide me on this please.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2017 15:07:13 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2017-12-05T15:07:13Z</dc:date>
    <item>
      <title>why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311846#M2709</link>
      <description>&lt;P&gt;Hi All,  Currently facing an issue in parsing the data and also the data is not conformed with CIM model. &lt;/P&gt;

&lt;P&gt;Environment details :&lt;BR /&gt;
F5 LTM data are being ingested into splunk Environment from syslogs servers. We have 5 Heavy forwarder instances configured to fetch the syslogs data's and forward it to the 5 individual indexer instances. Splunk F5 Add-on is uploaded in search head cluster master with the below configuration details as per the splunk documentation. &lt;BR /&gt;
appserver&lt;BR /&gt;
 bin&lt;BR /&gt;
 default&lt;BR /&gt;
 metadata&lt;BR /&gt;
 static&lt;BR /&gt;
 ReadME&lt;/P&gt;

&lt;P&gt;We have customize app Test-IA-f5 with the inputs.conf configured to fetch the data from the syslog server and this app is placed in all the Heavy forwarder instances. &lt;/P&gt;

&lt;P&gt;Test-IA-f5:&lt;/P&gt;

&lt;H1&gt;F5 LTM&lt;/H1&gt;

&lt;P&gt;[monitor:///opt/syslogs/web_access/.../*.log]&lt;BR /&gt;
index = web_app&lt;BR /&gt;
 sourcetype = f5:bigip:syslog&lt;BR /&gt;
host_segment = 4&lt;/P&gt;

&lt;P&gt;We could see the data in splunk console but data is not parsing properly and also its conformed with the CIM model. &lt;BR /&gt;
Kindly guide me how to fix this issue.&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:00:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311846#M2709</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T17:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311847#M2710</link>
      <description>&lt;P&gt;Does the indexed data show up as having sourcetype &lt;CODE&gt;f5:bigip:syslog&lt;/CODE&gt;?  Have you tried searching in verbose mode to confirm that none of the fields are being parsed as expected?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 01:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311847#M2710</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-11-27T01:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311848#M2711</link>
      <description>&lt;P&gt;Hi micahkemp,  thanks for your effort on this, yes when we try to search with the above source type we are able to see the data in splunk console.   But its not parsing the data as expected. I am came to know that we need to place the  splunk Add-on for F5 BIG-IP in the Heavy forwarder instances to parse the data before indexing the data. &lt;/P&gt;

&lt;P&gt;But I have question now, since i am using the sourcetype = f5:bigip:syslog do I need to place entire content of the splunk Add-on in the HF server or we can place only the props/transforms related to the sourcetype=f5:bigip:syslog is enough. &lt;/P&gt;

&lt;P&gt;Kindly guide me on this please.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 15:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311848#M2711</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-05T15:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311849#M2712</link>
      <description>&lt;P&gt;Based on the documentation &lt;A href="http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Sourcetypes"&gt;http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Sourcetypes&lt;/A&gt; , it says &lt;CODE&gt;f5:bigip:syslog&lt;/CODE&gt; sourcetype does not support any CIM datamodel. Have you checked that?&lt;/P&gt;

&lt;P&gt;EDIT: But while looking at the add-on, it is doing index level parsing and as you are using Heavy Forwarder to send syslog data with sourcetype &lt;CODE&gt;f5:bigip:syslog&lt;/CODE&gt; you need to install this add-on on Heavy Forwarder not on Indexers.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 15:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311849#M2712</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-05T15:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311850#M2713</link>
      <description>&lt;P&gt;Hi Harsmarvania57, thanks for your effort on this, I had placed the Splunk Add-on for F5 BIG-IP in the Heavy forwarder instances to parse the data before indexing the data.  After placing the add-on in the HF instance now we could see the F5 data are being parsed. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 11:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311850#M2713</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-12-06T11:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311851#M2714</link>
      <description>&lt;P&gt;I have converted my comment to answer, please accept it so that question will be closed.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 11:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311851#M2714</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-06T11:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: why the data is not conformed with CIM model after implementing the splunk Add-on for F5 BIG-IP?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311852#M2715</link>
      <description>&lt;P&gt;@harsmarvania57  can you help, we are also facing same issue . We have installed the F5 add-on on HF;however, logs are not getting tag to datamodel .&lt;/P&gt;

&lt;P&gt;All F5 syslog data is written into file (via UDP) and splunk is reading the files . sourcetype=f5:bigip:syslog   .&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 23:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/why-the-data-is-not-conformed-with-CIM-model-after-implementing/m-p/311852#M2715</guid>
      <dc:creator>sumitkathpal292</dc:creator>
      <dc:date>2018-11-27T23:22:59Z</dc:date>
    </item>
  </channel>
</rss>

