Getting Data In

how can get syslog from F5 BIGIP with Universal Forwarder

payamhaddad
New Member

hi all,

we our splunk enterprise with this configuration:

1 universal forwarder
2 indexers in cluster
1 search head
1 SIEM

how can i send traffic to our splunk based on syslog ?

""when we define input in our forwarder with F5 IP address and UDP port 514 we can receive data also the forwarder sends data to indexers and we can see them by our new defined index, but the data is not usable/readable because of mis-configuration in TA/add-on.""
how can i configure add-on in such this structure ?

0 Karma

plarsenDST
Explorer

You can send the syslog traffic to syslog-ng running on the universal forwarder or a Heavy forwarder 514 UDP or TCP if you like even other ports.

Then ingest the logs on the heavy forwarder / UF as you would any other log.

I have found syslog-ng works well for collecting syslog data from various network devices and or appliances. Firewalls, proxies, mail gateways etc. Logs are broken down by hostname in the file structure if you set it up this way.

Data continues to log to syslog-ng when you are doing maintence on Splunk is one advantage.

p_gurav
Champion
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...