<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for F5 Access guide? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86406#M44122</link>
    <description>&lt;P&gt;I agree, I can't find a link to a manual anywhere.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Mar 2012 15:17:24 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2012-03-14T15:17:24Z</dc:date>
    <item>
      <title>Splunk for F5 Access guide?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86405#M44121</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Using Splunk for F5 Access app and trying send logs from firepass to splunk on port 514.&lt;BR /&gt;
However, the stats in the F5 Access Dashboard are incomplete. For example I can only see 4 or 5 users in the Connections by User in the last 24 hours chart, but on the firepass, it shows that there was over a 100 connected in the same timeframe..&lt;/P&gt;

&lt;P&gt;Is there a configuration guide available for how to configure both the Splunk / F5 Access app and the Firepass device? - I want to verify if my config is correct.&lt;/P&gt;

&lt;P&gt;Have tried Splunk support, but they haven't been very helpful and say there is no support for the F5 Access app.&lt;/P&gt;

&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2012 09:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86405#M44121</guid>
      <dc:creator>dooshiant</dc:creator>
      <dc:date>2012-03-07T09:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Access guide?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86406#M44122</link>
      <description>&lt;P&gt;I agree, I can't find a link to a manual anywhere.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2012 15:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86406#M44122</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2012-03-14T15:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Access guide?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86407#M44123</link>
      <description>&lt;P&gt;there is :&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.f5.com/pdf/solution-center/splunk-templates-for-apm.pdf"&gt;getting started guide&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2012 15:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86407#M44123</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-14T15:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Access guide?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86408#M44124</link>
      <description>&lt;P&gt;Hi MarioM,&lt;/P&gt;

&lt;P&gt;This guide is for APM which runs on the BigIP platform. Firepass is different and runs on another platform. I have set the sourcetype to firepass_log as stated in the pdf though, but getting only limited stats - not all users / events are being shown..&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2012 09:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86408#M44124</guid>
      <dc:creator>dooshiant</dc:creator>
      <dc:date>2012-03-16T09:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Access guide?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86409#M44125</link>
      <description>&lt;P&gt;yes i know firepass is dedicated ssl vpn and the only thing to do is configure remote syslog on firepass to send to splunk (no other choice than udp 514) and set the sourcetype as firepass_log.&lt;BR /&gt;
After the firepass dashboard is just an example then up to you to build your own.&lt;BR /&gt;
Splunk is not about app but doing you own reports/dashboard...&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2012 13:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-F5-Access-guide/m-p/86409#M44125</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-03-17T13:39:44Z</dc:date>
    </item>
  </channel>
</rss>

