How I did it - "Visualizing Data with F5 TS and Splunk"
FIRST and most important is I want to thank you Greg for putting this together. VERY helpful and I know we all appreciate how thorugh your documentation and instruction is. Very helpful to getting this up ourselves.
Now to an issue I was hoping you could give me a push in the right direction. I get the basic info but not the stats on anything looking for telemetryEventCategory=AVR and yes AVR is provisioned and TS is confirmed to be pushing data. Followed your instructions to the tee. We did have BIG-IQ but removed it from these boxes and confirmed big-iq is not enabled
tmsh list analytics global-settings all-properties
analytics global-settings {
avrd-debug-mode disabled
avrd-interval 300
disable-all-internal-logging disabled
ecm-address any6
ecm-port 443
enable-bigiq-configuration disabled
external-logging-publisher /Common/Shared/telemetry_publisher
offbox-protocol hsl
offbox-tcp-addresses none
offbox-tcp-port 443
partition Common
source-id none
tenant-id default
trigger-configuration-update disabled
use-ecm disabled
use-hsl disabled
use-offbox enabled
}
Appreciate any direction you can offer