Skip to content

Commit

Permalink
Update lp-f5_bigip.conf.tmpl
Browse files Browse the repository at this point in the history
  • Loading branch information
Mark Bonsack committed Apr 7, 2020
1 parent c0302e0 commit e77d426
Showing 1 changed file with 14 additions and 13 deletions.
27 changes: 14 additions & 13 deletions package/etc/conf.d/log_paths/lp-f5_bigip.conf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ log {
filter{
program("tmsh")
or program("mcpd")
or program("apmd")
or program("tmm\d?")
};
rewrite {
Expand All @@ -35,19 +36,19 @@ log {
parser { p_add_context_splunk(key("f5_bigip")); };
parser (compliance_meta_by_source);
rewrite { set("$(template ${.splunk.sc4s_template} $(template t_program_msg))" value("MSG")); };
} elif {
filter {
program('apmd')
};
rewrite {
set("f5_bigip", value("fields.sc4s_vendor_product"));
set("${PROGRAM}", value(".PROGRAM"));
subst('^\/(?:[^\/]+\/)+', "" , value(".PROGRAM"));
r_set_splunk_dest_default(sourcetype("f5:bigip:apm:syslog"), index("netops"), source("program:${.PROGRAM}"))
};
parser { p_add_context_splunk(key("f5_bigip")); };
parser (compliance_meta_by_source);
rewrite { set("$(template ${.splunk.sc4s_template} $(template t_program_msg))" value("MSG")); };
# } elif {
# filter {
# program('apmd')
# };
# rewrite {
# set("f5_bigip", value("fields.sc4s_vendor_product"));
# set("${PROGRAM}", value(".PROGRAM"));
# subst('^\/(?:[^\/]+\/)+', "" , value(".PROGRAM"));
# r_set_splunk_dest_default(sourcetype("f5:bigip:apm:syslog"), index("netops"), source("program:${.PROGRAM}"))
# };
# parser { p_add_context_splunk(key("f5_bigip")); };
# parser (compliance_meta_by_source);
# rewrite { set("$(template ${.splunk.sc4s_template} $(template t_program_msg))" value("MSG")); };
} elif {
filter {
program('^,f5_irule')
Expand Down

0 comments on commit e77d426

Please sign in to comment.