The-messenger_1
Aug 17, 2017Nimbostratus
Session variables available to splunk
We have been working to get Big-ip data, usable, into splunk. Working with our splunk engineer, we've found that splunk does not have all the data the I get with sessiondump --allkeys. Splunk is getting data from syslog and the analytics app via highspeed logging.
There will be lots of data that we'll want to explore with Splunk but my initial work is for APM session data. It would be very good, for example, to give our help desk a dashboard for OWA, ActiveSync, Sharepoint other services that employees use.
Using APM Session data to start with, is there data that cannot be pushed to splunk? If so, why is that? If not, what do I need to do to get all session data into splunk?