Forum Discussion
F5 timestamp inquiry
Hello, we have a logfile being monitored by F5 that includes a syslog-formatted timestamp. When F5 reads the log and sends it to a secondary system, ex: Splunk, it appends another timestamp. Look at the example below with double the timestamps and server.
Feb 21 13:41:26 f5_monitor_server Feb 21 13:41:25 f5_dmz_server debug mcpd[6282]: save_master_key(7) called
What can we do to not wrap this additional timestamp and host ? I understand we can filter it out in Splunk but I don't want to waste the extra cycles as syslog is quite chatty.
Thanks
2 Replies
- Samir_Jha_52506
Noctilucent
Reviewed both the lines, Difference between logs timestamps are 1Sec. So i recommend to add one more timestamps column in splunk server.
- ifeldshteyn_384
Nimbostratus
Hi,
" I understand we can filter it out in Splunk but I don't want to waste the extra cycles as syslog is quite chatty."
I am trying to get rid of the timestamp on the F5 end, not on the Splunk end.
Thanks.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com