All Apps and Add-ons

,A10 Networks SLB

Conner40744
New Member

I am not getting data in the app itself but I see it in the index, I have updated the port in the props.conf do I also have to specify something for the source?

Source Typing

[source::udp:1301]
TRANSFORMS-st_for_slb = a10_slb
TRANSFORMS-st_for_waf = a10_waf

Avoids indexing keepalive msgs

TRANSFORMS-null_keepalive = a10_keepalive_null
,I am not getting data in the APP itself, I see data in the database but it isnt populating the app. I have changed the port in the props.conf

Source Typing

[source::udp:1301]
TRANSFORMS-st_for_slb = a10_slb
TRANSFORMS-st_for_waf = a10_waf

Avoids indexing keepalive msgs

TRANSFORMS-null_keepalive = a10_keepalive_null

Do I need to specify something for source also in this file?

Tags (1)
0 Karma

open3s
Explorer

Hi Conner40744,

Could you please check that the data source is the one that has been defined in your files?

If it's OK, please make sure that new props and transforms are applied.

You can restart Splunk to be sure.

Thanks,

Open3S,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...