All Apps and Add-ons

Add-on for F5 BIG-IP- Do I need to create another token to configure in the app?

BcWilliams
Engager

Attempting to configure modular inputs and not quiet understanding number 8. We have a HEC token already established for ingestion in the instance. Do I need to created another token to configure the in app? I've created local splunk_ta_setting.conf and set parameter enable_ssl =0 to configure the servers. Selected the templates 

 

 

  1. Go to Inputs. The Manage F5 Inputs page appears listing all inputs defined in the add-on.
  2. Click Create New Input to create a new input.
  3. Provide an input Name. Acceptable characters are a-z, A-Z, 0-9 or "_".
  4. (optional) Enter a Description for the input.
  5. Click Servers to select one or more servers from which you want to collect data.
  6. Click Templates to select one or more templates that describe the data you want to collect.
  7. Provide Polling Interval (in seconds) to set the data collection for the input. The add-on, by default, collects data from F5 servers for each input every 300 seconds. The interval setting determines the granularity of the data returned. The more often you collect data, the more detail you see from your data. If you specified a data collection interval when you configured your servers, that interval setting overrides the interval setting at the input level.
  8. Enter a HEC Token name to collect the data for the configured templates. For more information, see Creating a HEC Token. The user needs to make sure that the HEC Token is created in the Splunk_TA_f5 context. For that, the user will have to navigate to the Settings > Data Inputs from the Splunk_TA_f5 add-on. Also, you must disable the SSL check from Global Settings for the HEC Token to perform the Data Collection.
  9. Enter the Splunk Host to collect the data for a particular Splunk Instance.
  10. Click Add to create the input. The Splunk add-on for F5 BIG-IP creates the input, adds it to the list of scheduled inputs, and enables it by default. To disable the input at any time, click Disabled in the row for that input.

 While editing the inputs I get an Unexpected error  from python handler: "Stanza: Standard_System, Standard_Network, Standard_LocalLB does not exist in f5_templates_ts.conf

I've created f5_templates_ts.conf and added the stanzas for templates.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...