I have updated splunk to 8.0.1 and now the f5 app is not going well. I understand that the version is not yet compatible with this version of splunk, but I wanted to confirm if someone else is going through the same thing.
One of the problems are the tabs, they do not change
Yes, we ended up disabling HEC entirely from F5 and moving to Syslog. But the pre-baked queries on the old F5 apps are all kind of malformed and out of date. We're currently depending on viewing daily logs directly from the F5 to keep an eye on VPN users.