Forum Discussion

happynfocus_245's avatar
happynfocus_245
Icon for Nimbostratus rankNimbostratus
Feb 04, 2016

F5 ASM Splunk: source and host attributes have wrong data

I configured F5 ASM sending the alerts to splunk. At first I did not install any addons, and realized the logs are weird, and the source and host attributes have wrong data. The "host" attribute has the value "tcp:1514"

 

I then search the Splunk Apps and installed "Splunk Add-on for F5 BIG-IP." But even I launched "Splunk for F5 Security" to do the searching, it is the same result.

 

Any ideas? Thanks and really appreciate it!!

 

2 Replies

  • If your ASM is sending improperly formatted logs you need to open a case with support and have them look at it. They can help determine exactly what is happening and help get it fixed. You can reach support by calling 1-888-882-7525 or internationally 800 11 ASK 4 F5. Make sure you have your BigIP's serial number available as you will need it to open the case.

     

  • If your ASM is sending incorrectly formatted data to your splunk server, you need to contact support. They can help determine what is happening and help to get it fixed. You can reach support by calling 1-888-882-7525 or internationally 800 11 ASK 4 F5. Make sure you have your BigIP's serial number available as you will need it to open the case.