elastic / elastic/integrations

F5's logs (using syslog) are not parsed

Open
#7,236 8 comments 1 reaction 0 assignees View on GitHub
enhancement Integration:f5 Integration:f5_bigip mapping/pipeline issue Team:SDE-Crest Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 18h
Merged PRs (30d)
182

Description

# Overview

We are using F5 and trying to onboard the logs to Elasticsearch via Elastic Agent. We realized there are (at least) 2 types of logs:

1. Telemetry streaming data, which is target of our integration
- https://docs.elastic.co/integrations/f5_bigip
- https://clouddocs.f5.com/products/extensions/f5-telemetry-streaming/latest/quick-start.html
2. Usual log data which is available via syslog
- https://techdocs.f5.com/en-us/bigip-14-0-0/external-monitoring-of-big-ip-systems-implementations-14-0-0/about-logging.html

My understanding is our integration supports only 1st one. But we need to onboard 2nd one as well. So it will be super helpful for us if integration team introduces new input for 2nd usual syslog parsing.

# Sample logs

Currently we are using Custom TCP Logs integration to collect the syslog. Below are just example of the syslog messages which are taken from `message` field. Note that these are not complete list of the message type.

```
info logger[32640]: [ssl_acc] 10.200.20.200 - admin [03/Aug/2023:15:31:17 +0800] "/mgmt/shared/file-transfer/ucs-downloads/f5.bigiq-analytics-BIG-IQ.gz" 200 1111
info logger[32641]: [ssl_req][03/Aug/2023:15:31:17 +0800] 10.247.22.238 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 "/mgmt/shared/file-transfer/ucs-downloads/f5.bigiq-analytics-BIG-IQ.gz" 1111
info dhclient[11078]: XMT: Solicit on mgmt, interval 111800ms.
notice tmsh[9707]: 01420002:5: AUDIT - pid=9707 user=root folder=/ module=(tmos)# status=[Command OK] cmd_data=cd / ;
info
info systemd[1]: Starting user-0.slice.
info CROND[31708]: (root) CMD (/usr/bin/diskmonitor)
debug perl[31708]: OpenSSL is initialized in FIPS mode.
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.