Forum Discussion
Joe_Chapman_416
Jun 28, 2012Nimbostratus
Splunk for F5 Networks LTM v11 iRule
Hello, I've been struggling to get Splunk for F5 networks working properly. http://splunk-base.splunk.com/apps/50944/splunk-for-f5-networks There is an install guide that I've followed v...
GavinW_29074
Jul 02, 2012Nimbostratus
Joe
One quick thing to add from me.
We're using Splunk in our installation, with 2 pairs of F5 3900's in separate DC's.
Rather than relying on the Splunk built in syslog listener, we've installed syslog-ng, which allows you finer control over how to record logs, separate hosts, etc. We've then got Splunk configured to monitor those files on the local file-sys. There were some other benefits as well, but cant remember off the top of my head :)
This also means that we can restart Splunk without loosing any traffic data.
Oh, and one other thing...
I've created a second Splunk iRule for use with HTTPS VIPs, which adds the relevant SSL details to the Splunk log entries.
Can provide a copy if useful for you...
Cheers
Gavin
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects