Forum Discussion
Thomas_Gobet
Apr 11, 2014Nimbostratus
Pool status in Splunk for F5 Networks
Hi all,
I made some tests on Splunk with the 11.5.0 TMOS version.
My tests were on AFM, LTM and also syslog events.
LTM (with the iRule included) and AFM work fine, but for syslog events ther...
S__Kalynuk_1952
Apr 01, 2015Nimbostratus
For TMOS 11.5.1, I created a local/transforms.conf file with an updated REGEX that works:
[f5-syslog-eventcode]
REGEX = \]:\s(........:.):\sPool\s(\S+)\smember\s(\S+)\smonitor\sstatus\s\S+\.\s\[\s(\S+)\:\s(\S+)\s\]\s\s\[\swas\s(\S+)\sfor\s(\S+)
FORMAT = event_code::$1 ltm_pool::$2 ltm_member::$3 ltm_monitor::$4 ltm_monitor_status::$5 ltm_prevstatus::$6 ltm_prevstatus_time::$7
I added the ltm_monitor field although it isn't used by the app. The ltm_monitor_status is also extracted after the ltm_monitor field rather than after the "status" keyword.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects