Forum Discussion
Christian_15126
Nimbostratus
Dec 10, 2012f5 ltm sends syslog messages with local/ causing indexing issues with SPlunk
We are trying to point all our f5's to Splunk for syslog, but the default remote servers option is sending local/ in the syslog messages causing indexing issues with Splunk (it's reading them as loca...
Christophe_Thys
Nimbostratus
Jan 30, 2013Hi
I've got the same issue on 10.2.3 Build 112. My parsing engine cannot handle the hostname part containing "local/" in the hostname part.
Syslog message example:
Jan 30 15:14:37 local/MyHostname info logger: [ssl_req][30/Jan/2013:15:14:37 +0100] 192.168.0.3 TLSv1 DHE-RSA-AES256-SHA "POST /xxxx.cgi HTTP/1.1" 437
Any way we can remove that "local/" part?
Regards,
Christophe
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects