I have installed Splunk for F5 and the ASM Log Source type is not listed as an available source type for my logs.
I am running Splunk 4.1.3 Build 80534 for Windows.
Can someone tell me how to setup my data input as ASM Logs Source type?
Thanks.
Hi,
The sourcetype of your data must be asm_log. You have to define sourcetype=asm_log
in the inputs.conf file.
Exemple if you collect the logs through syslog :
[tcp://syslog.corp.company.net:514]
sourcetype = asm_log