Ahmed_Galal
Oct 07, 2019Cirrostratus
Splunk syslog loadbalancing
Hi All,
i have 2 Splunk Syslog server using UDP 514, splunk configure incoming logs upon source ip address so when i configured to load balance servers through F5 with automap it created one log file for all devices is there any solution can do X-Forward for UDP traffic in F5.
Hi
As syslog is fire and forget in nature, you probably don't need to use SNAT as there is no need for a return path. Try disabling SNAT on your VIP in the first instance.