All Apps and Add-ons

f5 asm .. reports blank

sandevsingh
New Member

Hi, I am trying to make f5 ASM and Splunk enterprise ver 7 work together. I have installed the "Splunk for F5 Security" app and I see the asm logs been indexed under it. But when I go to check the inbuilt reports from the App under Application Security manager > Web application stats OR security events stats OR any other report.. they are all blank! Saying " no results found". Any idea why this is happening?

thnx

Tags (1)
0 Karma

adonio
Ultra Champion

can be couple of things:
1. indexes read by default - if the searches that power the dashboards do not specify index=some_index and your user's role is not set up to search those indexes by default, you will see 'no results ...
2. sourcetype assignment is off / not working and therefor fields are not extracted correctly etc. try to run a search in
verbose` mode on the f5 data and see that all fields are extracted and sourcetypes are assigned.

hope it helps

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...