access logging
3 TopicsHelp with iRule logging to local0.
I am trying to log an iRule, but it keeps erroring out. Can you help with what I'm missing? when HTTP_REQUEST { if { [HTTP::path] starts_with "/media" } { pool persist cookie insert log local0. ”media.com_28080 TCP_logging fired, from [IP::client_addr]" } }6.8KViews0likes9CommentsAVR remote logging HSL pool
Dear All, I am trying to set up AVR remote logging to send web statistics to an external syslog server, but no traffic is being send at all. I configured the pool for sending syslog traffic. Configured ARV Analytics profile for external statistics logging type enabled. The log publisher named syslog used in the Analytics profile refers to the Syslog-ECM log destination. The syslog-ECM log destination is configured as type syslog and refers to the syslog pool. But traffic is not being send. If I use an Irule for sending logs to the destination it does work, it is not an IP connectivity issue but a more AVR specific one. Someone tried this out before, please leave your comments. Thanks331Views0likes0CommentsSession variables available to splunk
We have been working to get Big-ip data, usable, into splunk. Working with our splunk engineer, we've found that splunk does not have all the data the I get with sessiondump --allkeys. Splunk is getting data from syslog and the analytics app via highspeed logging. There will be lots of data that we'll want to explore with Splunk but my initial work is for APM session data. It would be very good, for example, to give our help desk a dashboard for OWA, ActiveSync, Sharepoint other services that employees use. Using APM Session data to start with, is there data that cannot be pushed to splunk? If so, why is that? If not, what do I need to do to get all session data into splunk?313Views0likes2Comments