Forum Discussion

KPS_149915's avatar
KPS_149915
Icon for Nimbostratus rankNimbostratus
Mar 03, 2017

Timestamp for F5 logs

Hi,

 

I have F5 in all continents and have centralized splunk logging in Europe. I want to sent all logs to sent to remote splunk log with the timestamp of the Europe not the timestamp of the F5 physical location. And also is it possible while i keep the logs locally in local database in F5 with local timestamp.

 

Thanks.

 

4 Replies

  • I guess, you will have to set local timestamp (based on location) in F5 to store respective location log local F5 db and send same log to splunk.But on spluñk shows two index timestamp one is for lb n other spluñk timestamp.

     

  • Thanks, i am concern about the timestamp for remote splunk as i need the requirement is to log in remote splunk server with splunk server timezone. Is there anything i have to configure in F5 to change the index or do it has to be done at splunk level.

     

  • Its interesting. Till now not tried to change index timestamp at spluñk leval. Will dig more n update you.

     

  • Hi!

     

    In this case I would rely on some Splunk magic when indexing rather than syslog-ng hacks.

     

    /Patrik