Splunk Enterprise Security

Getting F5 data into the data model of enterprise security

laurent_ripaux
New Member

The F5 logs are sent through the syslog to Splunk. However, the messages are not likely correctly cut out because many fields are populated with the "unknown" value. How can we deal with this? What should be the right configuration to correctly map the log data into the data models? Thank you for your reply. Regards, Laurent Ripaux

0 Karma

alemarzu
Motivator

Hi there @laurent.ripaux

Which app for F5 are you using ?

0 Karma

tmarlette
Motivator

that's a much more complicated question than you think it is.

field extraction is a long process in splunk using regex, and datamodel loading requires even creation, and then tagging. the 'unknown' value is equivalent to 'null', which you may not even want to load into your data model.

for instance, to generically load F5 data into the 'network' data model you'd have to create an event
eventtypes.conf

[f5_event]
search = index=network sourcetype=f5

Then tag it with 'network'. The above example assumes A LOT of other things are in place.
data models usually search for tags

0 Karma

laurent_ripaux
New Member

Thank you for this answer. We'll have to check the eventtypes.conf in place.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...