Forum Discussion
Joe_Chapman_416
Jun 28, 2012Nimbostratus
Splunk for F5 Networks LTM v11 iRule
Hello, I've been struggling to get Splunk for F5 networks working properly. http://splunk-base.splunk.com/apps/50944/splunk-for-f5-networks There is an install guide that I've followed v...
Joe_Chapman_416
Jun 29, 2012Nimbostratus
I must have something setup incorrectly still...
I don't think this matters, but I should mention that I'm using the VMWare virtual appliance
Here's what my interfaces look like on the LB
LB-HOSTxxx (this is where my web servers talk to the F5)
eth0
eth0:mgmtxxx
external xxx (where my SNAT and VIP addresses are)
internalxxx(HA network for redundant F5 pair)
lo127.0.0.1
lo:1127.2.0.2
tmm0127.1.1.1
my pool_syslog server sits at 10.245.50.52 with a port of 514 then a UDP check is enabled on it
Then on my log host I just setup a new interface with an ip address of 10.245.50.52 on eth2
Performing a tcpdump of all traffic on eth2 on the log host just shows me the message that's coming through on the health check...
[root@LOG01 10.245.50.11] tcpdump -ieth2
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth2, link-type EN10MB (Ethernet), capture size 65535 bytes
10:00:31.318348 IP xxx.50236 > 10.245.50.52.syslog: [|syslog]
10:00:36.281836 IP xxx.50236 > 10.245.50.52.syslog: [|syslog]
so the two can definitely talk, but i think my HSL traffic must still be going somewhere else..
Thanks
-Joe
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects