We have configured F5 int to splunk,What is the search condition to check F5 audit log in to splunk?
Please provide me the suggestion, so we can verify the same.
please check this sourcetype events - f5:bigip:syslog
if you have any sample events, we can create the splunk query.
Thanks, Please confirm F5 audit logs come in to f5:bigip:syslog or f5:bigip:1tm:http:irule.
Also share email id, I will send sample events.