Forum Discussion
Send data to 2 pool members in HSL pool
Hi Awan,
replicated option is for pool only not for publisher. In tmsh here is the syntax
create /sys log-config destination remote-high-speed-log <log destination name> distribution <adaptive|balanced|replicated> pool-name <HSL pool name> protocol <tcp|udp>
Log Publisher is step 4, first you need to creat log pools in step 1 then only you can go for log publishers:
Setting The BIG-IP into using HSL Steps.
- Create a Pool with the remote log server as the member.
- Go to System ›› Logs : Configuration : Log Destinations and create one of these two types of Destinations depending on whether you want to use TMM or management for the traffic.
- For a High Speed Logging Destination Click Create Select the pool you created in step 1.
- Name the Log Destination.
- Select 'Remote High-Speed Log'.
- Select the pool you created in step 1.
- Select TCP or UDP.
- Select the Distribution method (leave in default if only one pool member).
- Click Finished.
- To use the management interface (only one IP can be used in this method)
- Enter IP and port of logging server.
- Select Protocol.
- Click Finished.
- Now create another Log Destination (this will in essence trick the BIG-IP to use HSL logging).
- Choose type Splunk.
- Forward to either the HSL or management interface.
- Click Finished.
- Go to System ›› Logs : Configuration : Log Publishers
- Click Create.
- Name it.
- Choose the Destination from step 3.
- Click Finished.
The logging traffic proceeds from top to bottom in the illustration.
https://my.f5.com/manage/s/article/K17398
For your iRule, please refer below
open and send for HSL
https://clouddocs.f5.com/api/irules/HSL__open.html
https://clouddocs.f5.com/api/irules/HSL__send.html
https://my.f5.com/manage/s/article/K50040950
https://my.f5.com/manage/s/article/K50040950
https://clouddocs.f5.com/cli/tmsh-reference/v15/modules/ltm/ltm_rule_command_HSL_open.html
Please note
The protocol is case sensitive and must be specified in all uppercase letters.
Prior to 11.1 the protocol value is not validated when an iRule is saved, but will cause a run-time error when executed for a connection if the protocol is not valid (UDP or TCP).
The pool name is not validated when an iRule is saved but will cause a run-time error when executed if the pool does not exist.
HTH
F5 Design Engineer
🙏
- For a High Speed Logging Destination Click Create Select the pool you created in step 1.
- awan_mNov 07, 2023
Cirrostratus
Thanks for teh response - but this does not solve my Problem
My use case is -
i have - Acive and Standby F5s in 2 Data centers - F51 - DC -A , F52 - DC-B
i need to send all traffic to IDS appliance - so i connect one F5 interface to a switch in each datacenter that has the IDS device connected to it - and on each F5 i created a static ARP entry
what i want to do is create a pool that has both IDS devices in it - attach that pool to teh virtual server as client side clone pool and send traffic to both pool members -
any suggestions .
thanks
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com