Getting Data In

Having to restart heavy forwarder to get data from F5 network devices through control API

mamulani11
New Member

I have configured f5 network devices to a Heavy Forwarder. The data gets ingested for some time and then again it stops getting indexed. Every time I have to restart Splunk services on HF to start the indexing for F5 devices.
I got below error through internal logs on HF :

2019-06-19 14:53:17,812 ERROR pid=97727 tid=Thread-4677 file=F5_iControl_API.py:run:92 | Exception (it may be caused by unreachable F5 server "ip address" or wrong iControl API "Management.Folder.get_traffic_group" in configured template): Server raised fault: 'Exception caught in Management::urn:iControl:Management/Folder::get_traffic_group()

There are many errors like this.
Can someone please help me?

0 Karma

effem
Communicator

What Splunk Version and App are you using?

0 Karma

mamulani11
New Member

Splunk HF is 7.0.1 , For app I don't know how to check but if I check in apps.conf it is: 2.6.0(for f5 app)

0 Karma

effem
Communicator

This exception indicates a connectivity issue to your F5

0 Karma

mamulani11
New Member

Is it a fault from Splunk side or something with F5 devices itself? What can be done in such situations? How to resolve this issue?

0 Karma

mamulani11
New Member

Does anyone know about this, I am stuck not able to use this addon due to this issue

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...