Refine your search:

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

Splunk for F5 Networks is a colleciton of field extractions, saved searches, reports dashboards and web access iRule for your F5 Local Traffic Manager.

Splunk and F5 are working together to provide real time reporting and intelligence across the complete F5 product line. You rely on F5 Networks solutions like BigIP Global Traffic Manager, Local Traffic Manager, ASM, Firepass, WANOPT and ARX to keep your mission critical applications running and achieve IT agility. Your way. Now you can rely on Splunk for F5 to search, alert, report and make decisions in real time. Pre-defined inputs, searches, alerts, reports, dashboards and actions make it quick to get started and with the power of Splunk you can customize Splunk for F5 to meet the specific needs of your agile IT environment.

Versions and Release Notes

Version 1.0 (current version - updated Apr 05, 2013)
release notes:

* Added support for Application Delivery Firewall
* Update the Web Access iRule and supporting content. You will need to uninstall the beta version of the Web Access iRule.
* Updates made to pool availability

For Support please contact f5@splunk.com

show older versions »
Version 0.2 beta (updated Oct 21, 2011)
release notes:

- Fixed drill-down issue
- Added auto wilde carding to Server and Node name filters.

Version 0.1 beta (updated Oct 18, 2011)

posted 18 Oct '11, 02:26

splunk-f5's gravatar image

splunk-f5
511
accept rate: 0%

new version 05 Apr, 14:19


4 Reviews:
4 reviews, 3 ratings, average 1.33333

This app is extremely poorly written, documentation is lacking, updates are inconsistent, and the implementation seems very limiting for providing the data that it should from the F5. Overall we are extremely dissatisfied with the solution!

comments (0)

reviewed 17 Jul '12, 11:00

mcluver's gravatar image

mcluver
1
accept rate: 0%

edited 17 Jul '12, 11:13

Indeed this app needs some more work to be useable from the start. Few things that come to mind: - define specific indexes for raw f5 data and for the f5 summary index data - remove the 'Status' menu, the F5 app should not show the status of the splunk instance, there are other apps for that - improve the documentation of the different sourcetypes, the PDF doesn't even document which sourcetype the events should get for the UDP input - There's tons of dashboards that don't seem to be used and a lot of searches that are searching for not defined sourcetypes/sources - Some PNG images are missing, they seems to be still in the old F5 app, but not included in this version - ...

comments (0)

reviewed 08 Aug '12, 07:15

pietervi's gravatar image

pietervi
111
accept rate: 0%

edited 08 Aug '12, 09:51

To setup make sure your logs are set to sourcetype="F5_SPLUNK_iRULE"

Then under app/SplunkforF5/default/data/ui/views/trafficbyrequest.xml you change the search order to be

stats sum(count) as count by node | sort - count | head 10 instead of stats sum(count) as count by node | head 10 | sort - count

comments (0)

reviewed 08 Nov '12, 12:47

gseeto's gravatar image

gseeto
211
accept rate: 0%

I couldn't be more disappointed.

One thing that is painfully clear, is that the F5 has a high configurability for logging, yet this app gives no direction to how the syslog should be configured on the device to achieve the results that the app suggests.

mcluver hit the nail on the head.

comments (0)

reviewed 09 May, 08:56

jtrujillo's gravatar image

jtrujillo
1
accept rate: 0%

Your review

Did you find this app useful?

Preview toggle preview

Price: Free
Author: splunk-f5
Version: 1.0
Splunk compatibility: 4.3, 4.2, 4.1, 4.x, 3.x, 5.x
Updated:
License: Creative Commons BY 3.0

This app is not covered by any support agreements in place with Splunk. If you have questions about the installation or operation of this app, please contact the author.

Follow this app

Log In to enable email subscriptions

RSS:

Reviews

Reviews + Comments

Ask a Question
Copyright © 2005-2012 Splunk Inc. All rights reserved.