Splunk Enterprise

F5 for Security - Slow to load BIG-IP Hostname, and other dropdowns

MasterOogway
Communicator

Has anyone else experienced a deathly slow loading of the "BIG-IP Hostname" dropdown, or any other dropdown fields in the new "Splunk for F5 Security" App? We can search the data in normal display speeds, but once we move into the App and go do any of the ASM drop downs each field takes upwards of 5 minutes to load.
The "asm_log" has been set correctly in the inputs.conf...which is really the only requirement to have this App run correctly from the Index server side. The F5 is pushing data correctly because we can test that in a normal search.

Running v4.1.4
(2) Quad-Core processors; 48Gb Mem; (2) 146Gb SAS 10k HDD's; NAS storage for install & indexing.

On all previous installations over nine other environments, we have NEVER had an issue running on NAS as it is tuned to the "T's" for our Oracle installations.

Thoughts? Ideas? Anyone else experiencing this?

0 Karma

wagnerbianchi
Splunk Employee
Splunk Employee

I've got the same scenario on our tests with this app. We've implemented this app storing data upon a storage with 800 I/O per sec, moved to a SSD storage and now, we've ran upon a blade. On all scenarios we've observed the read operation too slow, after reaching 5GB of indexed data. Besides to it, we've looked for help to adjust configuration related to the app fields - the only field extration problem we've got this time is with field attack_type. Could you let me know if you've got problems with that mentioned field?

I am looking forward to hearing from you, tks!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...