All Apps and Add-ons

f5 asm .. reports blank

sandevsingh
New Member

Hi, I am trying to make f5 ASM and Splunk enterprise ver 7 work together. I have installed the "Splunk for F5 Security" app and I see the asm logs been indexed under it. But when I go to check the inbuilt reports from the App under Application Security manager > Web application stats OR security events stats OR any other report.. they are all blank! Saying " no results found". Any idea why this is happening?

thnx

Tags (1)
0 Karma

adonio
Ultra Champion

can be couple of things:
1. indexes read by default - if the searches that power the dashboards do not specify index=some_index and your user's role is not set up to search those indexes by default, you will see 'no results ...
2. sourcetype assignment is off / not working and therefor fields are not extracted correctly etc. try to run a search in
verbose` mode on the f5 data and see that all fields are extracted and sourcetypes are assigned.

hope it helps

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...