All Apps and Add-ons

Why Splunk Add on for F5 BIG IP doesn't separate sourcetypes?

badr_boukari
Explorer

Hello everyone, 

I am working right now to collect logs from F5 BIG-IP. I have a distributed Splunk Infrastructure: Heavy Forwarder, Indexer & Search Head. I installed the Splunk Add-on for F5 BIG-IP in the Search Head and Heavy Forwarer instances as recommended in Splunk documentation here:  https://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Install 

Then, i discovered that Splunk Add-on for F5 BIG-IP is not separating sourcetypes as expected !!! 

Also, maybe the last version of the Add-on for F5 BIG-IP (4.0.1) doesn't work with the version 16.0.0 of my F5 firewall. I read that somewhere ... But i am not sure about it! 

Anyone have an idea please? Or, when the Add-On will be updated to support it. 

PS : I'am working with Splunk Entreprise v8.0.4

Labels (2)
0 Karma

jbn_seb
Observer

@badr_boukari  I am also facing same issue. Have you fixed this? 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...