Forum Discussion
v11.5.3, ASM and Splunk
Hi everyone,
Has anyone managed to get the remote logging profile on v11.5.3 working with the Splunk for F5 Security app ? The transformers don't seem to match the data and I can't seem to force the sourcetype correctly when I have a mixture of syslog data coming out of the same source.
M.
3 Replies
it seems to behave relatively well with 11.6 for me when i just tested it. Top Attackers shows the data i expected. what is failing for you?
the second issue seems more a splunk one then BIG-IP i believe, perhaps you could do something with different ports?
- Mark_Wallis_833
Nimbostratus
Hi.
I think the latter problem is causing the former in my case. Can you confirm what 'sourcetype' is being applied to your ASM events for me ? I'll see if I can force it and make everything happier
Thanks Mark
sourcetype=asm_log
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com