Forum Discussion
Analytics IApp with Splunk
Good day,
I'm having some problems with installing the Analytics IApp, I was hoping some one can get me on the way.
I read the manuals and the video looks all pretty easy, but Its not working.
We are running Viprions, with multiple vCMPs on the blades. On each vCMP there runs a BigIP instance with multiple partitions. The common partition is not used.
How do I get this working. I tried to install the IApp in a vCMP in a partition, but then I get only errors that it is not possible to read files etc in the common partition. When I install the IApp in common I do not see any traffic send away to the Splunk server.
If some one can help me, would be appreciated!
Greetings, Robin
- Robin_BreggemanNimbostratus
Anyone?
Hi @Robin -
Login to the vCMP guest and run a tcpdump:
tcpdump -nni 0.0 host
You should see constant traffic on dst port 8088 (HTTPS port in iApp). Do you have basic connectivity to your splunk server with ping?
Are you using Splunk Enterprise? Have you tried a restart of the Splunk Server. Do you have enough data being sent to Splunk? Do you have the general "Define" matching in the iApp or are you matching on something specific? Wait 10 minutes after generating traffic to see it in Splunk.
And it MAY need to be run from the /Common partition. Unless there is a Release Candidate that fixes this to run in separate partitions.
Thanks!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com