All Apps and Add-ons

cannot see sourcetype=f5:bigip:asm:syslog logs explicitly

gchauhan
Engager

Hello Friends 
I am facing issues that may be caused by input.conf but I am not able to get bottom of the problem
when I search index=network "*f5*"

in which 2 types of sourcetype are coming 
f5:bigip:syslog
f5:bigip:asm:syslog

and certain event count against each sourcetype

when search index=network and sourcetype="*f5*", 

then under index=network
f5:bigip:ltm:tcl:error
f5:bigip:syslog

and certain event count against each sourcetype

but when I put index=network sourcetype="f5:bigip:asm:syslog"
no events is found

I am collecting the data from f5 on a server (HF) and collecting the data on indexer from HF. Add on are installed but I am not sure whether its configured.

Input.conf contains entry for f5:bigip:syslog

can someone please help

Regards
Gaurav
@prakash007 
@renjith_nair 
@jbsplunk 

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

Introducing New Splunkbase Governance!

Splunk apps are essential for maximizing the value of your Splunk Experience. Whether you’re using the default ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...