elastic / elastic/integrations

[F5 BigIP]: Enable Syslog TCP/UDP and Filestream inputs

Open
#20,899 0 comments 0 reactions 0 assignees View on GitHub
needs:triage
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 17h
Merged PRs (30d)
225

Description

### Integration Name

F5 BIG-IP [packages/f5_bigip]

### Dataset Name

f5_bigip.log

### Integration Version

1.28.0 (all versions)

### Agent Version

9.14.2 (all versions)

### OS Version and Architecture

N/A

### User Goal

This ER is to request adding a syslog input for F5 BigIP. TCP/UDP streaming and syslog formatted filestream input are being requested.

F5 BigIP supports syslog exports. This is the standard method that most organization use to get F5 data into a logging platform. Often sending to the same syslog port for all services/devices.

REF: https://my.f5.com/manage/s/article/K000137310

### Existing Features

F5 BigIP integration supports HTTP, AWS S3, and filestream (HTTP format only).

Syslog export is a standard method for most network services and falls into existing data collection pipelines. Having to set up the incredibly arduous API for F5 is something many customers have problems configuring and/or don't want to do as it makes the collection of F5 non-standard from their other network devices.

Splunk and other products collect syslog directly from the BigIP. This would allow us to offer a similar solution to our competitors and something the customer expects would already exist.

### What did you see?

Lack of syslog support

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Research direction

Start in packages/f5_bigip and inspect the existing HTTP, AWS S3, and filestream input definitions, along with the f5_bigip.log dataset configuration. Compare their configuration and parsing behavior with the requested TCP/UDP syslog and syslog-formatted filestream inputs. Done means the integration can collect both requested syslog forms and the f5_bigip.log dataset handles them correctly.

Written by the indexing model from the issue text.

Assessment

Domain
observability
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.