All Apps and Add-ons

How to ingest syslog data to Splunk App for F5 Networks?

padmajauk
Explorer

I have Splunk App for F5 Networks installed and have got F5 LTM and GTM log files with me. I don't have access to the BigIP system.
I tried Add Data option from Settings menu to upload file data. I have set sourcetype as syslog. However I don't see any of the F5 reports working in Splunk. Is the app supposed to work with data ingested from files. If yes, what exactly are the steps that I need to follow to make the app work

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

Do you have the syslog feeds coming into Splunk?

Have you followed the latest instructions with the app, located at : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Configureinputs ?

There are configuration changes that need to be made on the F5's in order to accommodate proper syslog formatting.

You should contact your F5 admins, and make sure your logging feeds are based on the following documentation to adhere to how the F5 app expects to see the data : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_F5_for_syslog

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Do you have the syslog feeds coming into Splunk?

Have you followed the latest instructions with the app, located at : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Configureinputs ?

There are configuration changes that need to be made on the F5's in order to accommodate proper syslog formatting.

You should contact your F5 admins, and make sure your logging feeds are based on the following documentation to adhere to how the F5 app expects to see the data : http://docs.splunk.com/Documentation/AddOns/latest/F5BIGIP/Setup#Configure_F5_for_syslog

View solution in original post

0 Karma

padmajauk
Explorer

Thanks for the quick response. I will contact F5 admins to make the required changes.

0 Karma

padmajauk
Explorer

Hi,

One more question. I have Splunk App for F5 Networks, and not the Splunk Add on for F5 Big-IP. The documentation url above refers to the AddOn. Is there any documentation for the Splunk App for F5 networks? How can I configure this app to pull syslog data from F5 system?

Thanks,
Padmaja