Splunk® Supported Add-ons

Splunk Add-on for F5 BIG-IP

Download manual as PDF

Download topic as PDF

Release notes for the Splunk Add-on for F5 BIG-IP

Version 2.7.0 of the Splunk Add-on for F5 BIG-IP was released on April 17, 2019.

Compatibility

Version 2.7.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.6.x, 7.0.x, 7.1.x, 7.2.x, 7.3.x
CIM 4.12
Platforms Platform independent
Vendor Products F5 BIG-IP 10.1 - 12.X. Licensed LTM, DNS (GTM), APM, and ASM modules.

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 2.7.0, by default data will be collected from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 BIG-IP Servers page (Configurations > Servers) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Add-on comparison
Splunk Add-on for F5 BIG-IP 2.7.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 6.5+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 2.7.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Date resolved Issue number Description
2019-03-04 ADDON-21320 JavaScript alerts don't show the actual error message
2019-02-10 ADDON-19342 Receiving error of Invalid key in stanza from default/log_info.conf
2019-02-06 ADDON-21018 Invalid field extractions in Sourcetype=f5:bigip:ltm:locallb:icontrol and Sourcetype=f5:bigip:apm:syslog

Known issues

Version 2.7.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:


Third-party software attributions

Version 2.7.0 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.

PREVIOUS
Source types for the Splunk Add-on for F5 BIG-IP
  NEXT
Release history for the Splunk Add-on for F5 BIG-IP

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters