Splunk Search

F5 ASM events are being merged, sourcetype is f5:bigip:asm:syslog

juanlazarosanch
New Member

I installed the Splunk Add-on for F5 BIG-IP and defined the incoming as sourcetype f5:bigip:asm:syslog. Several (not all) events are getting merged into one event. Is there anything I can change to modify the sourcetype so that each event is a single event and not merged? Thanks!

Tags (1)
0 Karma

prakash007
Builder

Did you check props and transforms in Splunk Add-on for F5 BIG-IP..??
Can you post a sample event here..??
Make sure you have that TA installed on a heavy forwarder or indexer.

0 Karma

juanlazarosanch
New Member

I checked for those files (props and transforms) but did not find them here, would they be in some other spot?
/opt/splunk/etc/apps/Splunk_TA_f5-bigip/local # ls
app.conf indexes.conf

The Splunk Add-on for F5 BIG-IP is installed on both the forwarder and indexer.

Unfortunately, I cannot post events. I can try redacting or modifying them before I post...it'll take me a while. Thanks!

0 Karma

prakash007
Builder

@juanlazarosanchez:
check it in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default...
when you say forwarder, is it a heavy forwarder or a universal forwarder..??

0 Karma

juanlazarosanch
New Member

Heavy forwarder

They were in the spot you used mentioned. I looked through them, but could not determine why the events were merging.

I tried something different, I changed to sourcetype to access_common and now all the events are separated as they should be. I don't mind using access_common going forward unless there is another pre-trained sourcetype that would be more appropriate.

0 Karma

prakash007
Builder

@juanlazarosanchez : I wouldn't do that unless there is a specific reason, go through splunk docs for detailed configuration steps, there should be few other configs/extractions that are tied with default sourcetypes.
http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Sourcetypes

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...