Tom_K_185554
Jun 01, 2018Nimbostratus
How can I get hsl logging in splunk to be in json format
Hello, I am using the f5.analytics.v3.7.0 Iapps template. I have an irule which I will provide below which we use to send some connection event data to splunk using hsl logging.
I have attached 2 new screen prints. The way is was described to me is that splunk is expecting to receive json formatted data. They said, think of all the red fields as field types and the light blue data as a value. Notice the field type that says syslog_message in red and the value next to it is the value in json format with one syslog message for each irule event. Then notice the all the red hsl output where it all appears to be a field with no value even though all the log information is present, to splunk it all just looks like one big field type. It also has all the events lumped together in one large message. So the goal is to get the hsl data to look like the syslog_message lines.