Forum Discussion
SPLUNK intergration with LTMv11- to send access log
Hi All, I have syslog configuration on LTM V11.4 right now to send syslog to SPLUNK. I only see system related log on splunk. But I want to see access log on splunk for reporting, including the source ip address of the client and other http request details.
can you help how i can configure LTM to sent all the access log to splunk?
thanks
2 Replies
Hi TT,
beginning with TMOS v11.2 APM-Logs will be forwarded to SYSLOG by default. You may check the APM log publisher settings...
System ›› Logs : Configuration : Log Publishers ›› sys-db-access-publisher... to confirm that local-syslog ist enabled.
For further information see SOL13394:
https://support.f5.com/kb/en-us/solutions/public/13000/300/sol13394.html
Cheers, Kai
You could use analytics in combination with the BIG-IP splunk app https://devcentral.f5.com/codeshare/f5-analytics-iapp
Cheers,
Kees
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com