Forum Discussion
BIG-IP syslog include
- Sep 12, 2024
We have validated this on Version 17.x and are working on other versions as well. Here is the link to the article.
Using use_fqdn(no) in syslog configuration still includes the hostname/FQDN in the logs. (f5.com)
I'm happy to have this exposed as "Solution". Perhaps with a shorter title.😀I edited the original.
I updated it with frac_digits(6); to get microseconds as the logger seems to support that.
Output from F5s does NOT appear to be RFC5424 compliant with this change. For example, I see an ascii level indicator which rfc5424 does not include. I'm looking into further validation.
The F5s should really have built in support to log in rfc5424 with short names, timezone and milli/microsecond information. Supporting only fqdn and only rfc3164 is pretty lame in this day and age.
There are a few F5 KB articles that recommend adding udp() to syslog include. udp() has been deprecated for a long time now. Any KB references that include that should be updated.
BIG-IP 15.1.10.3 includes syslog-ng 3.8.1 which no longer has reliable online documentation that I can find. If F5 is going to continue to ship this old version, they should at least post the documentation online. syslog-ng 3.8.1 shipped on Aug 19, 2016:
https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-3.8.1
- LiefZimmermanSep 12, 2024Admin
Unfortunately, for now, I can't see to mark multiple items as Solution.
When I can I will do so for this comment as well.Thanks again Tim - very helpful.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com