All Apps and Add-ons

How to ingest syslog data to Splunk App for F5 Networks?

padmajauk
Explorer

I have Splunk App for F5 Networks installed and have got F5 LTM and GTM log files with me. I don't have access to the BigIP system.
I tried Add Data option from Settings menu to upload file data. I have set sourcetype as syslog. However I don't see any of the F5 reports working in Splunk. Is the app supposed to work with data ingested from files. If yes, what exactly are the steps that I need to follow to make the app work

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Do you have the syslog feeds coming into Splunk?

Have you followed the latest instructions with the app, located at : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Configureinputs ?

There are configuration changes that need to be made on the F5's in order to accommodate proper syslog formatting.

You should contact your F5 admins, and make sure your logging feeds are based on the following documentation to adhere to how the F5 app expects to see the data : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_F5_for_syslog

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Do you have the syslog feeds coming into Splunk?

Have you followed the latest instructions with the app, located at : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Configureinputs ?

There are configuration changes that need to be made on the F5's in order to accommodate proper syslog formatting.

You should contact your F5 admins, and make sure your logging feeds are based on the following documentation to adhere to how the F5 app expects to see the data : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_F5_for_syslog

0 Karma

padmajauk
Explorer

Thanks for the quick response. I will contact F5 admins to make the required changes.

0 Karma

padmajauk
Explorer

Hi,

One more question. I have Splunk App for F5 Networks, and not the Splunk Add on for F5 Big-IP. The documentation url above refers to the AddOn. Is there any documentation for the Splunk App for F5 networks? How can I configure this app to pull syslog data from F5 system?

Thanks,
Padmaja

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...