All Apps and Add-ons

Splunk F5 for Networks Question

gnovak
Builder

I installed the Splunk for F5 networks on an indexer that only has network data. So far the data we have is:

pix
asa
f5
switch
iostat

I'm trying to get this app to work but i can't find a manual on this app anywhere. I noticed other posts that said you have to have your sourcetype be "F5_SPLUNK_iRULE".

What source has to have this sourcetype? F5 logs only? Pix logs?

Also, since I already have my network logs assigned sourcetypes (which i listed above) can I make a secondary sourcetype as well for these logs?

I'd really like to utilize this app but the fact there rare no instructions for this is really discouraging.

0 Karma
1 Solution

MarioM
Motivator

The Splunk for F5 Networks is based on f5 ltm traffic which is not logged in default syslog and need irule to get it logged to remote syslog.

The instructions are inside the app as well as the iRule:

splunk/etc/apps/SplunkforF5Networks/Installing Splunk for F5 Big.pdf

splunk/etc/apps/SplunkforF5Networks/irule.txt

Regarding the sourcetype you can use: Manager » Fields » Sourcetype renaming to rename the existing sourcetype.

Sourcetypes to work with different app

F5 LTM default syslog > ltm_log

F5 LTM Traffic log generated by iRule > F5_SPLUNK_iRULE

Splunk for Cisco firewall add-on > cisco_asa, cisco_pix

View solution in original post

0 Karma

MarioM
Motivator

The Splunk for F5 Networks is based on f5 ltm traffic which is not logged in default syslog and need irule to get it logged to remote syslog.

The instructions are inside the app as well as the iRule:

splunk/etc/apps/SplunkforF5Networks/Installing Splunk for F5 Big.pdf

splunk/etc/apps/SplunkforF5Networks/irule.txt

Regarding the sourcetype you can use: Manager » Fields » Sourcetype renaming to rename the existing sourcetype.

Sourcetypes to work with different app

F5 LTM default syslog > ltm_log

F5 LTM Traffic log generated by iRule > F5_SPLUNK_iRULE

Splunk for Cisco firewall add-on > cisco_asa, cisco_pix
0 Karma

gnovak
Builder

Thanks for the info!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...