We have installed the add-on available on Splunkbase for F5 BIG-IP LTM, but some events are not being properly mapped to their corresponding event information. Additionally, the default sourcetype being used is syslog. we installed this add on on SH and HF respectively. Events also shows event type = f5_bigip_syslog_audit_process sample events contains below messages obj_delete create_if modify monitor status up monitor status down Anyone face this issue or find something helpful to improve or make some changes on add on
... View more