All Apps and Add-ons

Why Splunk Add on for F5 BIG IP doesn't separate sourcetypes?

badr_boukari
Explorer

Hello everyone, 

I am working right now to collect logs from F5 BIG-IP. I have a distributed Splunk Infrastructure: Heavy Forwarder, Indexer & Search Head. I installed the Splunk Add-on for F5 BIG-IP in the Search Head and Heavy Forwarer instances as recommended in Splunk documentation here:  https://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Install 

Then, i discovered that Splunk Add-on for F5 BIG-IP is not separating sourcetypes as expected !!! 

Also, maybe the last version of the Add-on for F5 BIG-IP (4.0.1) doesn't work with the version 16.0.0 of my F5 firewall. I read that somewhere ... But i am not sure about it! 

Anyone have an idea please? Or, when the Add-On will be updated to support it. 

PS : I'am working with Splunk Entreprise v8.0.4

Labels (2)
0 Karma

jbn_seb
Observer

@badr_boukari  I am also facing same issue. Have you fixed this? 

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...