Thanks For Downloading!Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows: Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into Unix/Linux: Decompress the downloaded file using a tool like DescriptionSplunk for F5 Networks is a colleciton of field extractions, saved searches, reports dashboards and web access iRule for your F5 Local Traffic Manager. Versions and Release Notes
Version 1.0 (current version - updated Apr 05, 2013)
release notes:
* Added support for Application Delivery Firewall For Support please contact f5@splunk.com
Version 0.2 beta
(updated Oct 21, 2011)
release notes:
- Fixed drill-down issue
Version 0.1 beta
(updated Oct 18, 2011)
|
This app is extremely poorly written, documentation is lacking, updates are inconsistent, and the implementation seems very limiting for providing the data that it should from the F5. Overall we are extremely dissatisfied with the solution!
Indeed this app needs some more work to be useable from the start. Few things that come to mind: - define specific indexes for raw f5 data and for the f5 summary index data - remove the 'Status' menu, the F5 app should not show the status of the splunk instance, there are other apps for that - improve the documentation of the different sourcetypes, the PDF doesn't even document which sourcetype the events should get for the UDP input - There's tons of dashboards that don't seem to be used and a lot of searches that are searching for not defined sourcetypes/sources - Some PNG images are missing, they seems to be still in the old F5 app, but not included in this version - ...
To setup make sure your logs are set to sourcetype="F5_SPLUNK_iRULE"
Then under app/SplunkforF5/default/data/ui/views/trafficbyrequest.xml you change the search order to be
stats sum(count) as count by node | sort - count | head 10 instead of stats sum(count) as count by node | head 10 | sort - count
I couldn't be more disappointed.
One thing that is painfully clear, is that the F5 has a high configurability for logging, yet this app gives no direction to how the syslog should be configured on the device to achieve the results that the app suggests.
mcluver hit the nail on the head.