I am getting message from "default send string" form F5.bigip.addon why this happening could any one put some light on this. whether the problem from f5 server side or H.F side
TRANSFORM-null = remove_junk
REGEX=default send string
Use this config where parsing happens.
This string is being sent from the F5 UDP monitor that you have assigned to the Splunk pool. You can stop it by removing the monitor from the pool but then you will not be alerted when the pool is not responding. By default the monitor is sent every 5 seconds which can be increased to whatever value you want it to be. If you do so then make sure you also increase the Timeout value as well. BTW, you should not change the default UDP monitor you should create a new one and use the default one as the parent. Obviously, that only reduces the events. What I did was:
1. Created a new udp time, udp_splunk. Increased the Interval to 60. Set Timeout to 181. Set Send String to "2020-01-01T01:01:01Z F5monitor"
2. Filtered out the monitor events using TRANSFORMS-null.
Adding the hardcoded timestamp to the send string will eliminate the "failed to parse timestamp" errors.
same goes for us, I'm assuming this is a string sent from F5? Is there a BIG-IP setting/config that we can change to limit or stop this additional data?
<777>DEC 11 09:34:56 corp.LB logger: [ssl_acc] 192.168.0.0 - admin [11/DEC/2017:09:34:56 -0700] "/mgmt/XXX/XXXX/XXXXXX" 200 2 default send string default send string <777>DEC 11 10:37:16 corp.LB logger: [ssl_acc] 192.168.0.0 - admin [11/DEC/2017:10:37:16 -0700] "/mgmt/XXX/XXXX/XXXXXX" 200 2 default send string default send string default send string