All Apps and Add-ons

cannot see sourcetype=f5:bigip:asm:syslog logs explicitly

gchauhan
Engager

Hello Friends 
I am facing issues that may be caused by input.conf but I am not able to get bottom of the problem
when I search index=network "*f5*"

in which 2 types of sourcetype are coming 
f5:bigip:syslog
f5:bigip:asm:syslog

and certain event count against each sourcetype

when search index=network and sourcetype="*f5*", 

then under index=network
f5:bigip:ltm:tcl:error
f5:bigip:syslog

and certain event count against each sourcetype

but when I put index=network sourcetype="f5:bigip:asm:syslog"
no events is found

I am collecting the data from f5 on a server (HF) and collecting the data on indexer from HF. Add on are installed but I am not sure whether its configured.

Input.conf contains entry for f5:bigip:syslog

can someone please help

Regards
Gaurav
@prakash007 
@renjith_nair 
@jbsplunk 

Labels (3)
Tags (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...