Forum Discussion

Alexei_Barabash's avatar
Alexei_Barabash
Icon for Nimbostratus rankNimbostratus
Dec 24, 2017

ASM Logs to Splunk

Hey ,

 

I was wondering if i can manipulate the logs that are coming from my F5-ASM and goes to Splunk , that it will be displayed differently.

 

for example i use

 

 

I want Splunk to see this \r\n as line-break.

 

But still no luck with this.

 

Anyone tried this ?

 

  • Syslog is message-oriented format. The ASM logs are sent as single UDP/TCP records, and the configured CRLF is just a part of the message.

     

    You may be able to configure Splunk to split the messages based on the CRLF separator (I think Splunk has a message preprocessor), but that would be a question to ask Splunk.