Forum Discussion
Display logs and last change on LTM via automation !!
Hi All
We have couple of BIG-IP LTM devices (1900, 3600, 6900) and I face 2 issues on daily basis:-
1 - LTMs are out of synch most of the time. These are mostly because of any change in the configuartion (where we forgot the sych the configuration to other peer) or any other activity on the LTM in general.
is it possible that I can do some sutomation here so that I can list last couuple of changes since it was in synch state.
2 - Most of the time, Application teams wants to go through the logs i.e. they want to inquire about a particular Pool member when it was down during last 7 days or month etc. For that I have to run long commands and I feel it time consuming.
is it posisble that we can do some automation here so that we can mention the object to be searched from logs, Date and Time and we information is displayed.
News with F5 and tryiing to learn how all automation works.
Thanks in advance !!
Khiali
3 Replies
- Kevin_Stewart
Employee
In both cases you may want to consider:
-
Enabling MCP logging (logs changes to the configuration).
-
Configuring syslog to send MCP logs to a remote data collection and analysis service (like Splunk). There you'll get all of the GUI-based query capabilities that you need.
-
Optional to 1 and 2 above, if your platforms support Log Publishing, you can configure a filter to collect debug message from MCP and MCPD and send to remote syslog via high speed logging.
On the platforms that support 11.4, you can also enable auto-sync between HA pairs.
-
- khiali_130513
Nimbostratus
I want to get a script which I can hand over to other teams who want to check logs periodically or during troubleshooting so they are not dependent on network team.
We can`t use splunk in our network as it os not yet apprived by management. we are using version 10.x
- Kevin_Stewart
Employee
Simply put, BIG-IP dumps information to syslog (local and/or remote) and generates SNMP data. You can configure it to log as much or as little as you want, and event be somewhat specific about what you log. But it does not have the built-in log correlation and filtering functions that you may be looking for. You either need to acquire such a product, or build scripts to do the filtering on the box (bash, grep, sed, awk, etc.).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com