<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429953#M174139</link>
    <description>&lt;P&gt;I checked for those files (props and transforms) but did not find them here, would they be in some other spot?&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_TA_f5-bigip/local # ls&lt;BR /&gt;
app.conf  indexes.conf&lt;/P&gt;

&lt;P&gt;The Splunk Add-on for F5 BIG-IP is installed on both the forwarder and indexer.&lt;/P&gt;

&lt;P&gt;Unfortunately, I cannot post events.  I can try redacting or modifying them before I post...it'll take me a while.  Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:21:15 GMT</pubDate>
    <dc:creator>juanlazarosanch</dc:creator>
    <dc:date>2020-09-29T22:21:15Z</dc:date>
    <item>
      <title>F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429951#M174137</link>
      <description>&lt;P&gt;I installed the Splunk Add-on for F5 BIG-IP and defined the incoming as sourcetype f5:bigip:asm:syslog.  Several (not all) events are getting merged into one event.  Is there anything I can change to modify the sourcetype so that each event is a single event and not merged?  Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 19:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429951#M174137</guid>
      <dc:creator>juanlazarosanch</dc:creator>
      <dc:date>2018-12-12T19:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429952#M174138</link>
      <description>&lt;P&gt;Did you check props and transforms in Splunk Add-on for F5 BIG-IP..??&lt;BR /&gt;
Can you post a sample event here..??&lt;BR /&gt;
Make sure you have that TA installed on a heavy forwarder or indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 19:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429952#M174138</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-12T19:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429953#M174139</link>
      <description>&lt;P&gt;I checked for those files (props and transforms) but did not find them here, would they be in some other spot?&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_TA_f5-bigip/local # ls&lt;BR /&gt;
app.conf  indexes.conf&lt;/P&gt;

&lt;P&gt;The Splunk Add-on for F5 BIG-IP is installed on both the forwarder and indexer.&lt;/P&gt;

&lt;P&gt;Unfortunately, I cannot post events.  I can try redacting or modifying them before I post...it'll take me a while.  Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429953#M174139</guid>
      <dc:creator>juanlazarosanch</dc:creator>
      <dc:date>2020-09-29T22:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429954#M174140</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207045"&gt;@juanlazarosanch&lt;/a&gt;ez: &lt;BR /&gt;
check it in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default...&lt;BR /&gt;
when you say forwarder, is it a heavy forwarder or a universal forwarder..?? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429954#M174140</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2020-09-29T22:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429955#M174141</link>
      <description>&lt;P&gt;Heavy forwarder&lt;/P&gt;

&lt;P&gt;They were in the spot you used mentioned.  I looked through them, but could not determine why the events were merging.&lt;/P&gt;

&lt;P&gt;I tried something different, I changed to sourcetype to access_common and now all the events are separated as they should be.  I don't mind using access_common going forward unless there is another pre-trained sourcetype that would be more appropriate.  &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429955#M174141</guid>
      <dc:creator>juanlazarosanch</dc:creator>
      <dc:date>2020-09-29T22:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429956#M174142</link>
      <description>&lt;P&gt;@juanlazarosanchez : I wouldn't do that unless there is a specific reason, go through splunk docs for detailed configuration steps, there should be few other configs/extractions that are tied with default sourcetypes.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Sourcetypes"&gt;http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Sourcetypes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 01:14:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-ASM-events-are-being-merged-sourcetype-is-f5-bigip-asm-syslog/m-p/429956#M174142</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-13T01:14:29Z</dc:date>
    </item>
  </channel>
</rss>

