All Apps and Add-ons

F5 Networks - Analytics (New): How do I get the rest of my data into the app?

Waltersr24
New Member

I'm looking to see what I need to do to get the rest of the data in the F5 Networks - Analytics (New) app. I currently am not getting any data for the expiring SSL certificates, recent virtual changes, and recent pool changes. I followed on the pre-release PDF document and the video. I'm not sure what I should be looking for to get the data in.

0 Karma

evolutionxtinct
Explorer

@Waltersr24

Just wanted to let you know I got this fixed, if you use Splunk 7.1.2 and F5-BIGIP 13.1.0+ use the F5 Analytics iApp v3.7.2RC5, I had this issue and was resolved using this version of the F5 Analytics iApp.

evolutionxtinct
Explorer

I'm in the same boat after getting F5 Analytics installed, and configured in Splunk Enterprise 7.1.2. When I enable Syslog data, I get that data in splunk but I see no other data. The only errors I see are these:

Jan  4 04:00:30 f5-n1 notice mcpd[5856]: 0107167d:5: Data publisher not found or not implemented when processing request (unknown request), tag (2901).
Jan  4 04:00:35 f5-n1 err scriptd[13853]: 014f0013:3: Script (/Common/Splunk-send_stats) generated this Tcl error: (script did not successfully complete: (01020036:3: The requested RADIUS Server (/Common/Splunk.app) was not found.     while executing "tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth"     invoked from within "lindex [tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth] 0"     invoked from within "set obj [lindex [tmsh::get_config auth radius-server /Common/$appname.app/$radius_ihealth] 0]" line:41))

I've gone over the Deployment guide from F5 and everything is configured as it should be.

0 Karma

suarezry
Builder

If you are seeing some events but not others then the first troubleshooting step is to SSH to the F5 LTM and look at /var/log/ltm to see if there are any errors with the transfer to splunk.

0 Karma

evolutionxtinct
Explorer

This seems to be an error in my LTM log, but I can't get any where w/ community and Tier 1 support.

/Common/Splunk.app was not found

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...