All Apps and Add-ons

Do I have to have AFM licensed?

gehogan3
Explorer

I really would like to start pushing my F5 logs (both GTM and LTM) into Splunk and I am happy to see there is "Splunk for F5 Networks"...however, the Doc that accompanies the app is all about setting up logging for the "Advanced Firewall Manager"...which, of course, I do not have.

Is "Splunk for F5 Networks" still useful for only LTM and GTM logs, and is there some documentation for configuring it?

Thanks!

-Emmett

0 Karma

rblair978
Explorer

To report on Traffic and Rule hits (Items underneath App Delivery Firewall) features are licensed in AFM.

The pool stats come from BIG-IP system logs.
In the BIG-IP GUI: System --> Logs --> Configuration --> Log Filters
Create a new entry. Give it a name, specify your severity, and choose your Log Publisher.

The Web Access Stats come from the included iRule.
http://:/en-US/static/app/SplunkforF5Networks/gettinstarted.pdf

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...