Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How to send BIGIP virtual Server Logs[HSL] to ELK #40

Open
f5killer opened this issue Sep 2, 2021 · 1 comment
Open

How to send BIGIP virtual Server Logs[HSL] to ELK #40

f5killer opened this issue Sep 2, 2021 · 1 comment

Comments

@f5killer
Copy link

f5killer commented Sep 2, 2021

Hi Team,

Wanted to send BIGIP virtual Server Logs[HSL] to ELK and publish it also. but feel "logstash.conf" is not enough.

F5 Bigip is sending log to ELK logstach.

{"type":"response","@timestamp":"2021-09-01T18:09:48Z","tags":[],"pid":245,"method":"post","statusCode":200,"req":{"url":"/elasticsearch/_msearch?rest_total_hits_as_int=true&ignore_throttled=true","method":"post","headers":{"host":"3.87.141.156:5601","connection":"keep-alive","content-length":"919","accept":"application/json, text/plain, /","kbn-version":"7.4.2","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36","content-type":"application/x-ndjson","origin":"http://3.87.141.156:5601","referer":"http://3.87.141.156:5601/app/kibana","accept-encoding":"gzip, deflate","accept-language":"en-US,en;q=0.9,hi;q=0.8"},"remoteAddress":"223.235.12.xxx","userAgent":"223.235.12.xxxx","referer":"http://3.87.141.156:5601/app/kibana"},"res":{"statusCode":200,"responseTime":12,"contentLength":9},"message":"POST /elasticsearch/_msearch?rest_total_hits_as_int=true&ignore_throttled=true 200 12ms - 9.0B"}

Can you please help me to create the logstash file.

@464d41
Copy link
Contributor

464d41 commented Sep 13, 2021

Hi,

Seems to work for me with latest logstash config, BIG-IP v15.1, ELK 7.1. Please give more details on your setup. @f5killer

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants