Forum Discussion

DEAD_BEEF_39022's avatar
DEAD_BEEF_39022
Icon for Nimbostratus rankNimbostratus
May 09, 2019

How do I identify log types going to syslog from F5 devices?

(please ignore TECHNOLOGY tag, I had to pick 1 to post)

 

Hello everyone. I manage a Splunk instance and am attempting to sort F5 logs I am receiving. My syslog is receiving 13 different log files from the "F5 devices" but no one can tell me what the logs are or how to group/categorize them (break them into different sourcetypes). I asked the network engineer but haven't heard anything in weeks so I'm reaching out for your help. Any advice on how to go about determining what is what would be appreciated.

 

The logs are being sent to my syslog server and then getting picked up by Splunk. The 13 different log files are all .log :

 

auth, authpriv, cron, daemon, kern, local0, local1, local2, local4, local6, mail, syslog, user