I installed the Splunk Add-on for F5 BIG-IP and defined the incoming as sourcetype f5:bigip:asm:syslog. Several (not all) events are getting merged into one event. Is there anything I can change to modify the sourcetype so that each event is a single event and not merged? Thanks!
I checked for those files (props and transforms) but did not find them here, would they be in some other spot?
/opt/splunk/etc/apps/Splunk_TA_f5-bigip/local # ls
The Splunk Add-on for F5 BIG-IP is installed on both the forwarder and indexer.
Unfortunately, I cannot post events. I can try redacting or modifying them before I post...it'll take me a while. Thanks!
They were in the spot you used mentioned. I looked through them, but could not determine why the events were merging.
I tried something different, I changed to sourcetype to access_common and now all the events are separated as they should be. I don't mind using access_common going forward unless there is another pre-trained sourcetype that would be more appropriate.
@juanlazarosanchez : I wouldn't do that unless there is a specific reason, go through splunk docs for detailed configuration steps, there should be few other configs/extractions that are tied with default sourcetypes.