<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: F5 BIG IP'S Security iRule in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22172#M43717</link>
    <description>&lt;P&gt;We followed the steps available on the pdf which came within the app file. But, the field attack_type is reporting just commas, " and "" - anyone know about that, is it is normal or not? Any advise? Are there anyone using this app who can collaborate?&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2013 15:02:23 GMT</pubDate>
    <dc:creator>wagnerbianchi</dc:creator>
    <dc:date>2013-05-02T15:02:23Z</dc:date>
    <item>
      <title>F5 BIG IP'S Security iRule</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22171#M43716</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hello Splunkers, how have you been?&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;We've been taking with F5 BIG IP Security (WAF) app and we've been observing some strange behavior on panel's dashboards, most of that connected with Attacks and Signatures. I think the way we've configured the iRule or something on BIG IP panel is not correctly right. Just adding more information, we've configured data input via UDP.&lt;/P&gt;

&lt;P&gt;The main concern is:&lt;BR /&gt;
 1. how to generate these logs?&lt;BR /&gt;
 2. how to configure the way BIG IP way generate these logs?&lt;BR /&gt;
 3. Is this related with iRule?&lt;/P&gt;

&lt;P&gt;Could you guys help? Thanks a lot for any suggestion.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 12:02:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22171#M43716</guid>
      <dc:creator>wagnerbianchi</dc:creator>
      <dc:date>2013-05-02T12:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: F5 BIG IP'S Security iRule</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22172#M43717</link>
      <description>&lt;P&gt;We followed the steps available on the pdf which came within the app file. But, the field attack_type is reporting just commas, " and "" - anyone know about that, is it is normal or not? Any advise? Are there anyone using this app who can collaborate?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 15:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22172#M43717</guid>
      <dc:creator>wagnerbianchi</dc:creator>
      <dc:date>2013-05-02T15:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: F5 BIG IP'S Security iRule</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22173#M43718</link>
      <description>&lt;P&gt;This seem like a F5 BIG IP specific issue.  You may want to also post on DevCenteral.  I am only familar with the icontrol interface.  What does a raw event look like&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2013 16:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22173#M43718</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2013-05-02T16:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: F5 BIG IP'S Security iRule</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22174#M43719</link>
      <description>&lt;P&gt;OK! For ones who want to keep track this conversation, I just did a recap on a thread in which is being discussed the same subject. It is at: &lt;A href="https://devcentral.f5.com/community/group/aft/1172058/asg/39#2276926"&gt;https://devcentral.f5.com/community/group/aft/1172058/asg/39#2276926&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers, WB&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 13:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22174#M43719</guid>
      <dc:creator>wagnerbianchi</dc:creator>
      <dc:date>2013-05-03T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: F5 BIG IP'S Security iRule</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22175#M43720</link>
      <description>&lt;P&gt;So, I'm here again so as to try to be helped by you Splunk guys. &lt;/P&gt;

&lt;P&gt;On DevCentral nobody has given a feedback yet, what follows:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Just to recap this conversation which you've started some times ago (ASM &amp;amp; Splunk integration), I am getting problems in get Splunk fully functional after follow the steps part of the pdf file which came with the app's package. The field attack_type, used in many queries of the first app menu's group, is presenting, I imagine, wrong data. it is presenting graphs with symbols as commas, double quotes and single quotes. I will count on your help so as to understand whether it is a problem or not...could you give me a hand on that? Thanks a lot and looking forward to hearing from you.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I confess that I am little lost in midst of this implementation, but, this time I am looking forward to gather all the stuffs I've learned and check out what is wrong with the field attach_type, present on many dashboards generated by this app. It is getting just symbols as commas and single and double quotes. It's not represent anything and this is my only concern at this time.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is it wrong on BIG IP log profile configuration?&lt;/LI&gt;
&lt;LI&gt;Is it wrong on Splunk when you uncomment a line on app's props.conf?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It will very interesting that someone who is taking or has took with this app give a little help on that, perhaps F5 can help either!&lt;/P&gt;

&lt;P&gt;I will appreciate any help...cheers!!&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2013 19:16:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/F5-BIG-IP-S-Security-iRule/m-p/22175#M43720</guid>
      <dc:creator>wagnerbianchi</dc:creator>
      <dc:date>2013-05-04T19:16:55Z</dc:date>
    </item>
  </channel>
</rss>

