I really would like to start pushing my F5 logs (both GTM and LTM) into Splunk and I am happy to see there is "Splunk for F5 Networks"...however, the Doc that accompanies the app is all about setting up logging for the "Advanced Firewall Manager"...which, of course, I do not have.
Is "Splunk for F5 Networks" still useful for only LTM and GTM logs, and is there some documentation for configuring it?
Thanks!
-Emmett
To report on Traffic and Rule hits (Items underneath App Delivery Firewall) features are licensed in AFM.
The pool stats come from BIG-IP system logs.
In the BIG-IP GUI: System --> Logs --> Configuration --> Log Filters
Create a new entry. Give it a name, specify your severity, and choose your Log Publisher.
The Web Access Stats come from the included iRule.
http://