<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for F5 Networks in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128632#M34923</link>
    <description>&lt;P&gt;Can you elaborate on the sourcetypes you see within the search part of the F5 app?  Looking at the transforms I see that it is doing sourcetype rewriting.  Is this app installed on the indexing tier as well, otherwise it is probably not rewriting the sourcetype at index time.&lt;/P&gt;

&lt;P&gt;[f5-syslog]&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
REGEX = (01070727:5|01070638:5)&lt;BR /&gt;
FORMAT = sourcetype::F5:LTM:Syslog&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2014 11:27:01 GMT</pubDate>
    <dc:creator>dmaislin_splunk</dc:creator>
    <dc:date>2014-04-11T11:27:01Z</dc:date>
    <item>
      <title>Splunk for F5 Networks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128631#M34922</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I've installed Splunk for F5 Networks application to make some tests on it.&lt;BR /&gt;
I'm using 11.5 TMOS version and there's something wrong on the regex it uses.&lt;/P&gt;

&lt;P&gt;I made some changes on it to match informations needed but it still doesn't work, could you confirm me that it's into  /opt/splunk/etc/apps/SplunkforF5Networks/default/transforms.conf every transformations are done ?&lt;/P&gt;

&lt;P&gt;Here is the newest regex which include old and new format of syslog events :&lt;BR /&gt;
/]:\s(........:.):\sPool\s(\S+)\smember\s(\S+)\smonitor\sstatus\s(\S+).\s?[?\s?(?:\S+)?:?\s?(?:\S+)?\s?]?\s+?[\swas\s(\S+)\sfor\s(\S+)/&lt;/P&gt;

&lt;P&gt;Thanks in advance for your response &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 10:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128631#M34922</guid>
      <dc:creator>bowzom</dc:creator>
      <dc:date>2014-04-11T10:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Networks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128632#M34923</link>
      <description>&lt;P&gt;Can you elaborate on the sourcetypes you see within the search part of the F5 app?  Looking at the transforms I see that it is doing sourcetype rewriting.  Is this app installed on the indexing tier as well, otherwise it is probably not rewriting the sourcetype at index time.&lt;/P&gt;

&lt;P&gt;[f5-syslog]&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
REGEX = (01070727:5|01070638:5)&lt;BR /&gt;
FORMAT = sourcetype::F5:LTM:Syslog&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 11:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128632#M34923</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2014-04-11T11:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for F5 Networks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128633#M34924</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;

&lt;P&gt;My problem is not on f5-syslog event but on f5-syslog-eventcode, which is just below the one you saw.&lt;/P&gt;

&lt;P&gt;[f5-syslog-eventcode]&lt;BR /&gt;&lt;BR /&gt;
REGEX = /]:\s(........:.):\sPool\s(\S+)\smember\s(\S+)\smonitor\sstatus\s(\S+).\s[\s(?:\S+):\s(?:\S+)\s]\s+[\swas\s(\S+)\sfor\s(\S+)/&lt;BR /&gt;
FORMAT = event_code::$1 ltm_pool::$2 ltm_member::$3 ltm_monitor_status::$4 ltm_prevstatus::$5 ltm_prevstatus_time::$6&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 12:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-F5-Networks/m-p/128633#M34924</guid>
      <dc:creator>bowzom</dc:creator>
      <dc:date>2014-04-11T12:08:28Z</dc:date>
    </item>
  </channel>
</rss>

