<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Entries in F5 Network App not populating data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452846#M128202</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am getting LTM, ASM, APM logs from F5 devices over UDP port 9514 and I have bifurcated the  inputs.conf file and I am able to find the sourcetype entries in normal search. Whereas I am unable to see any entries in F5 Network App.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 08:39:47 GMT</pubDate>
    <dc:creator>singriajay</dc:creator>
    <dc:date>2019-07-01T08:39:47Z</dc:date>
    <item>
      <title>Entries in F5 Network App not populating data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452846#M128202</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am getting LTM, ASM, APM logs from F5 devices over UDP port 9514 and I have bifurcated the  inputs.conf file and I am able to find the sourcetype entries in normal search. Whereas I am unable to see any entries in F5 Network App.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 08:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452846#M128202</guid>
      <dc:creator>singriajay</dc:creator>
      <dc:date>2019-07-01T08:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Entries in F5 Network App not populating data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452847#M128203</link>
      <description>&lt;P&gt;What index is the F5 data stored in? Does your role search that index by default? Either way, the app should specify an index macro, but it only does sourcetypes. If you don't have the index searched by default it won't point to an index to search. You can update this in &lt;BR /&gt;
 &lt;CODE&gt;Settings--&amp;gt;Advanced Configuration--&amp;gt;Search Macros&lt;/CODE&gt; and then navigate to the F5 app. For each of the macros append  &lt;CODE&gt;index=&amp;lt;your-F5-index&amp;gt;&lt;/CODE&gt; to the beginning of the macro.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 16:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452847#M128203</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-07-01T16:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Entries in F5 Network App not populating data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452848#M128204</link>
      <description>&lt;P&gt;I am using the "main" index as of now. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;f5_index&lt;/CODE&gt; source=$kpi_type$ where1="$where1$" where2="$where2$" is the content present in the app. Should I append for all the macros with index=main  in place of &lt;CODE&gt;f5_index&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:08:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452848#M128204</guid>
      <dc:creator>singriajay</dc:creator>
      <dc:date>2020-09-30T01:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Entries in F5 Network App not populating data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452849#M128205</link>
      <description>&lt;P&gt;So it does look like it uses an index macro. I must have been looking at the wrong F5 Network app. Then my answer still applies. Go to &lt;CODE&gt;Settings--&amp;gt;Advanced Configuration--&amp;gt;Search Macros&lt;/CODE&gt; and find &lt;CODE&gt;f5_index&lt;/CODE&gt;. You should see it define index=. Just change that to main and it should change throughout the entire app.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 11:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452849#M128205</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2019-07-02T11:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Entries in F5 Network App not populating data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452850#M128206</link>
      <description>&lt;P&gt;This is working fine. Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:16:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Entries-in-F5-Network-App-not-populating-data/m-p/452850#M128206</guid>
      <dc:creator>singriajay</dc:creator>
      <dc:date>2019-07-02T13:16:29Z</dc:date>
    </item>
  </channel>
</rss>

