All Apps and Add-ons

i am getting default send string logs from f5 bigip addon

kumarpraveen
Engager

Hi all

I am getting message from "default send string" form F5.bigip.addon why this happening could any one put some light on this. whether the problem from f5 server side or H.F side

saravanan90
Contributor

In props.conf
[host::F5sendingIp]
TRANSFORM-null = remove_junk


In transforms.conf
[remove_junk]
REGEX=default send string
DEST_KEY=queue
FORMAT=nullQueue

Use this config where parsing happens.

0 Karma

kurtkite
New Member

This string is being sent from the F5 UDP monitor that you have assigned to the Splunk pool. You can stop it by removing the monitor from the pool but then you will not be alerted when the pool is not responding. By default the monitor is sent every 5 seconds which can be increased to whatever value you want it to be. If you do so then make sure you also increase the Timeout value as well. BTW, you should not change the default UDP monitor you should create a new one and use the default one as the parent. Obviously, that only reduces the events. What I did was:
1. Created a new udp time, udp_splunk. Increased the Interval to 60. Set Timeout to 181. Set Send String to "2020-01-01T01:01:01Z F5monitor"
2. Filtered out the monitor events using TRANSFORMS-null.

Adding the hardcoded timestamp to the send string will eliminate the "failed to parse timestamp" errors.

0 Karma

dijikul
Communicator

Any luck with this?

0 Karma

georgen_splunk
Splunk Employee
Splunk Employee

same goes for us, I'm assuming this is a string sent from F5? Is there a BIG-IP setting/config that we can change to limit or stop this additional data?

<777>DEC 11 09:34:56 corp.LB logger: [ssl_acc] 192.168.0.0 - admin [11/DEC/2017:09:34:56 -0700] "/mgmt/XXX/XXXX/XXXXXX" 200 2
default send string
default send string
<777>DEC 11 10:37:16 corp.LB logger: [ssl_acc] 192.168.0.0 - admin [11/DEC/2017:10:37:16 -0700] "/mgmt/XXX/XXXX/XXXXXX" 200 2
default send string
default send string
default send string
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...