Forum Discussion
Pool status in Splunk for F5 Networks
I tried the following to see if it would grab it, but no luck yet...
In Splunk my syslog message was <133>1 2014-09-19T15:29:05-06:00 localhost.localdomain mcpd 6649 01070727:5: [F5@12276 hostname="localhost.localdomain" errdefs_msgno="01070727:5:"] Pool /Common/dvwa_pool member /Common/192.168.0.217:80 monitor status up. [ /Common/dvwa_monitor: up ] [ was down for 0hr:0min:10sec ]
My RegEX = REGEX = /\serrdefs_msgno="(........:.)\S+\sPool\s(\S+)\smember\s(\S+)\smonitor\sstatus\s(\S+).\s?[?\s?(?:\S+)?:?\s?(?:\S+)?\s?]?\s+?[\swas\s(\S+)\sfor\s(\S+)/
In RegEx teter it loks good, but no joy here. I will keep trying....
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com