<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic F5 LTM: default send string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31392#M178109</link>
    <description>&lt;P&gt;A Splunk customer of mine has set up the Irule to communicate with Splunk and take advantage of the Splunk for f5 Networks.  The only thing that is sent udp:514 to splunk is what appears to be just a test message: "default send string".  &lt;/P&gt;

&lt;P&gt;Very novice at BigIP LTM, but know splunk pretty well....any suggestions on what needs to be configured on the LoadBalancer to get more robust logging?&lt;/P&gt;

&lt;P&gt;BTW: It is not a sourcetype issue. This is the only syslog message we get from the loadbalancer at the moment.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2011 15:28:38 GMT</pubDate>
    <dc:creator>davecroto</dc:creator>
    <dc:date>2011-12-08T15:28:38Z</dc:date>
    <item>
      <title>F5 LTM: default send string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31392#M178109</link>
      <description>&lt;P&gt;A Splunk customer of mine has set up the Irule to communicate with Splunk and take advantage of the Splunk for f5 Networks.  The only thing that is sent udp:514 to splunk is what appears to be just a test message: "default send string".  &lt;/P&gt;

&lt;P&gt;Very novice at BigIP LTM, but know splunk pretty well....any suggestions on what needs to be configured on the LoadBalancer to get more robust logging?&lt;/P&gt;

&lt;P&gt;BTW: It is not a sourcetype issue. This is the only syslog message we get from the loadbalancer at the moment.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2011 15:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31392#M178109</guid>
      <dc:creator>davecroto</dc:creator>
      <dc:date>2011-12-08T15:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: F5 LTM: default send string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31393#M178110</link>
      <description>&lt;P&gt;BTW:  It is not a sourcetype issue.  This is the only syslog message we get from the loadbalancer at the moment.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2011 15:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31393#M178110</guid>
      <dc:creator>davecroto</dc:creator>
      <dc:date>2011-12-08T15:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: F5 LTM: default send string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31394#M178111</link>
      <description>&lt;P&gt;Can you post a sanitized irule he's using?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2011 17:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31394#M178111</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-12-08T17:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: F5 LTM: default send string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31395#M178112</link>
      <description>&lt;P&gt;This is the step by step guide about setting up the syslog forwarding on the BigIP LTM &lt;/P&gt;

&lt;P&gt;&lt;A href="http://support.f5.com/kb/en-us/solutions/public/8000/200/sol8260.html"&gt;http://support.f5.com/kb/en-us/solutions/public/8000/200/sol8260.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2011 04:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/F5-LTM-default-send-string/m-p/31395#M178112</guid>
      <dc:creator>ppang</dc:creator>
      <dc:date>2011-12-09T04:03:18Z</dc:date>
    </item>
  </channel>
</rss>

