All Apps and Add-ons

Why Splunk Add on for F5 BIG IP doesn't separate sourcetypes?

badr_boukari
Explorer

Hello everyone, 

I am working right now to collect logs from F5 BIG-IP. I have a distributed Splunk Infrastructure: Heavy Forwarder, Indexer & Search Head. I installed the Splunk Add-on for F5 BIG-IP in the Search Head and Heavy Forwarer instances as recommended in Splunk documentation here:  https://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Install 

Then, i discovered that Splunk Add-on for F5 BIG-IP is not separating sourcetypes as expected !!! 

Also, maybe the last version of the Add-on for F5 BIG-IP (4.0.1) doesn't work with the version 16.0.0 of my F5 firewall. I read that somewhere ... But i am not sure about it! 

Anyone have an idea please? Or, when the Add-On will be updated to support it. 

PS : I'am working with Splunk Entreprise v8.0.4

Labels (2)
0 Karma

jbn_seb
Observer

@badr_boukari  I am also facing same issue. Have you fixed this? 

0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...