All Apps and Add-ons

f5 LTM events are not properly mapped by available add on

hussainladak
Engager

We have installed the add-on available on Splunkbase for F5 BIG-IP LTM, but some events are not being properly mapped to their corresponding event information. Additionally, the default sourcetype being used is syslog. we installed this add on on SH and HF respectively. Events also shows event type = f5_bigip_syslog_audit_process

sample events contains below messages
obj_delete
create_if 
modify
monitor status up
monitor status down

Anyone face this issue or find something helpful to improve or make some changes on add on

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @hussainladak 

Just to check, is it the 'Splunk Add-on for F5 BIG-IP' app you have installed? 

The docs for the app (https://splunk.github.io/splunk-add-on-for-f5-big-ip/Prepare_F5_Servers_For_Telemetry/) provide details on how best to set up the data ingestion. If you are using syslog approach then the recommendation is to use Splunk Connect for Syslog (SC4S) however if you are using native syslog into Splunk then you need to set the sourcetype to f5:bigip:syslog. 

More info on syslog ingestion is available at https://splunk.github.io/splunk-add-on-for-f5-big-ip/Obtain_Syslog_Data/

Once the sourcetype is defined correctly the app should hopefully provide the appropriate field extractions etc.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...