All Apps and Add-ons

cannot see sourcetype=f5:bigip:asm:syslog logs explicitly

gchauhan
Engager

Hello Friends 
I am facing issues that may be caused by input.conf but I am not able to get bottom of the problem
when I search index=network "*f5*"

in which 2 types of sourcetype are coming 
f5:bigip:syslog
f5:bigip:asm:syslog

and certain event count against each sourcetype

when search index=network and sourcetype="*f5*", 

then under index=network
f5:bigip:ltm:tcl:error
f5:bigip:syslog

and certain event count against each sourcetype

but when I put index=network sourcetype="f5:bigip:asm:syslog"
no events is found

I am collecting the data from f5 on a server (HF) and collecting the data on indexer from HF. Add on are installed but I am not sure whether its configured.

Input.conf contains entry for f5:bigip:syslog

can someone please help

Regards
Gaurav
@prakash007 
@renjith_nair 
@jbsplunk 

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...