Getting Data In

F5 index not properly captured

WilliamF
Engager

How to check if f5 logs are getting into Splunk properly?

Tags (2)

wagnerbianchi
Splunk Employee
Splunk Employee

I am not sure if you are referring to a Splunk for F5 Security, but, I am having some problems related to the extractions done by this app. I followed all the steps available on pdf which came with the app (that once named Creating-a-logging-profile-for-Splunk) and I noticed that when a fields is extracted, it is being extracted field_name=value, not just the field's value. It is being a problem to filter data because the website names into the combo boxes are being extracted the same way either. I wonder if there are additional configs to generate event logs which are not part of that available doc.

Someone having similar problems, I say, related with extractions done by this app?

Thanks for any help.

0 Karma

piebob
Splunk Employee
Splunk Employee

what does 'properly' mean? are you seeing the events in the index? have you tried searching for something you know should be in the events, over all time?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...