All Apps and Add-ons

Splunk for F5 Data Input method

apro
Path Finder

Hi,

Have just installed SplunkForF5 app. Would like to check on the methods to configure data input for it?

Tags (2)

cnk
Path Finder

Have you configured a network input listening on port 514 on the Splunk side? By default the app is configured for the following inputs:

[tcp://9998]
sourcetype = asm_log

[monitor:///home/sheyda/SplunkData/asm_full_dos]
disabled = 1
host = sheyda-laptop
host_regex = 
host_segment = 
index = default
sourcetype = asm_log

[monitor:///home/sheyda/SplunkData/dos_log]
disabled = 1
host = sheyda-laptop
host_regex = 
host_segment = 
index = default
sourcetype = as

[monitor:///home/sheyda/SplunkData/psm_splunk]
disabled = 1
host = sheyda-laptop
host_regex = 
host_segment = 
index = default
sourcetype = psm_log

[monitor:///var/log]
disabled = 1
host = sheyda-laptop
host_regex = 
host_segment = 
index = default
sourcetype = 
[tcp://9997]
sourcetype = psm_log

Most of these seem to be very specific to where the application creator was storing their logs.

If you're only going to be sending over Firepass logs using 514/UDP then you could configure inputs.conf like this:

[udp://514]
sourcetype = firepass_log

apro
Path Finder

Tried to send in logs from Firepass on udp 514 but doesn't seem to receive any yet.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...