Forum Discussion
F5 timestamp inquiry
Hello, we have a logfile being monitored by F5 that includes a syslog-formatted timestamp. When F5 reads the log and sends it to a secondary system, ex: Splunk, it appends another timestamp. Look at the example below with double the timestamps and server.
Feb 21 13:41:26 f5_monitor_server Feb 21 13:41:25 f5_dmz_server debug mcpd[6282]: save_master_key(7) called
What can we do to not wrap this additional timestamp and host ? I understand we can filter it out in Splunk but I don't want to waste the extra cycles as syslog is quite chatty.
Thanks
- Samir_Jha_52506Noctilucent
Reviewed both the lines, Difference between logs timestamps are 1Sec. So i recommend to add one more timestamps column in splunk server.
- ifeldshteyn_384Nimbostratus
Hi,
" I understand we can filter it out in Splunk but I don't want to waste the extra cycles as syslog is quite chatty."
I am trying to get rid of the timestamp on the F5 end, not on the Splunk end.
Thanks.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com