All Apps and Add-ons

Why Splunk Add on for F5 BIG IP doesn't separate sourcetypes?

badr_boukari
Explorer

Hello everyone, 

I am working right now to collect logs from F5 BIG-IP. I have a distributed Splunk Infrastructure: Heavy Forwarder, Indexer & Search Head. I installed the Splunk Add-on for F5 BIG-IP in the Search Head and Heavy Forwarer instances as recommended in Splunk documentation here:  https://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Install 

Then, i discovered that Splunk Add-on for F5 BIG-IP is not separating sourcetypes as expected !!! 

Also, maybe the last version of the Add-on for F5 BIG-IP (4.0.1) doesn't work with the version 16.0.0 of my F5 firewall. I read that somewhere ... But i am not sure about it! 

Anyone have an idea please? Or, when the Add-On will be updated to support it. 

PS : I'am working with Splunk Entreprise v8.0.4

Labels (2)
0 Karma

jbn_seb
Observer

@badr_boukari  I am also facing same issue. Have you fixed this? 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...