#Random
This is a place to discuss all things outside of Splunk, its products, and its use cases.

F5 big-ip sys log pool member

Denversh
Observer

Hi  Friend,

I am getting my Big- ip logs in syslog format on my single splunk deployment instance and I am having trouble figuring out the proper way to Change the name of values. TO ( Disabled , Forced Offline , Enabled) 

Note: The "pool_member_new_session_enable 1 pool_member_monitor_state 3" means the pool member is manually Disabled.

** pool_member_update_status 1 pool_member_new_session_enable 1 pool_member_monitor_state 3  **
 
Note: The "pool_member_new_session_enable 1 pool_member_monitor_state 20" indicates the pool member is manually Forced Offline.

**pool_member_update_status 1 pool_member_new_session_enable 1 pool_member_monitor_state 20 **
 
Note: The "pool_member_new_session_enable 2 pool_member_monitor_state 3" means the pool member is manually Enabled.

**pool_member_update_status 1 pool_member_new_session_enable 2 pool_member_monitor_state 3 **
 
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...