Skip to content

Release history for the Splunk Add-on for F5 BIG-IP

Latest release

The latest release of the Splunk Add-on for F5 BIG-IP is version 6.4.0. See Release notes for the Splunk Add-on for F5 Big-IP for the release notes of this latest version.

Version 6.3.0

Version 6.3.0 of the Splunk Add-on for F5 BIG-IP was released on September 3, 2024.

Compatibility

Version 6.3.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 9.0.x, 9.1.x
CIM 5.2.0
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 17.1.0 Licensed LTM, DNS (GTM), APM, AFM, and ASM modules.

New Features

  • Fixed the security vulnerabilities found in the urllib3, certifi, and idna library by upgrading the version from 1.26.18 to 1.26.19 2024.2.2 to 2024.7.4 and 3.6 to 3.7 respectively
  • Support of IPv6. Splunk Add-on for F5 BIG-IP v6.3.0 is now compatible with Splunk running on the IPv6 environment

Fixed issues

Version 6.3.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 6.3.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download: Splunk Add-on for F5 BIG-IP third-party software credits

Version 6.2.1

Version 6.2.1 of the Splunk Add-on for F5 BIG-IP was released on December 12, 2023.

Compatibility

Version 6.2.1 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.2.x, 9.0.x, 9.1.x
CIM 5.2.0
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 17.1.0 Licensed LTM, DNS (GTM), APM, AFM, and ASM modules.

New Features

  • Fixed the security vulnerabilities found in the urllib3 library by upgrading the version from 1.26.13 to 1.26.18.
  • Fixed an issue in updating the running inputs that were not modifiable by users post-Splunk restart.

Fixed issues

Version 6.2.1 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 6.2.1 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download: Splunk Add-on for F5 BIG-IP third-party software credits

Version 6.2.0

Version 6.2.0 of the Splunk Add-on for F5 BIG-IP was released on September 28, 2023.

Compatibility

Version 6.2.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.2.x, 9.0.x, 9.1.x
CIM 5.2.0
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 17.1.0 Licensed LTM, DNS (GTM), APM, AFM, and ASM modules.

New Features

  • Added support of the F5 BIG-IP product v17.1.0
  • CIM field enhancements for these sourcetypes:
    • f5:bigip:syslog - “Connection error” related events having source and destination address are mapped with Network Traffic CIM data model
    • f5:bigip:apm:syslog - “Assigned PPP”, “allow ACL”, “reject ACL” type of events are mapped to Network Traffic CIM data model
    • f5:bigip:apm:syslog - “New session from client IP” type of events are mapped to Network Session CIM data model
    • f5:bigip:gtm:dns:request:irule - events falling under this sourcetypes are mapped with Network Resolution DNS CIM data model
    • f5:bigip:ltm:ssl:error - “SSL Handshake Failed” type of events will be mapped under this sourcetype instead of f5:bigip:syslog and it will be mapped to Network Traffic CIM data model
  • Logger enhancements - There will be a separate log file for each of the inputs configured in the add-on and the naming convention will be splunk_ta_f5_bigip_input-<input_name>.log

It is recommended that the user first disables all the inputs, and then upgrades to the latest version of the add-on, so that it does not lead to any discrepancies in the logs of the input

Fixed issues

Version 6.2.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 6.2.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download: Splunk Add-on for F5 BIG-IP third-party software credits

Version 6.1.1

Version 6.1.1 of the Splunk Add-on for F5 BIG-IP was released on March 6, 2023.

Compatibility

Version 6.1.1 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.1.x, 8.2.x, 9.0.x
CIM 5.0.2
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 17.0.0 Licensed LTM, DNS (GTM), APM, AFM, and ASM modules.

New Features

  • Fixed a security vulnerability found in the certifi library.

Fixed issues

Version 6.1.1 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 6.1.1 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download: Splunk Add-on for F5 BIG-IP third-party software credits

Version 6.0.0

Version 6.0.0 of the Splunk Add-on for F5 BIG-IP was released on Mar 7, 2022.

Compatibility

Version 6.0.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.1.x, 8.2.x
CIM 5.0.0
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 16.1.0 Licensed LTM, DNS (GTM), APM, AFM, and ASM modules.

New Features

  • Migrated the data collection from the SOAP API to Telemetry Streaming. Users will have to reconfigure the Accounts, Templates and Inputs to start the data collection using Telemetry Streaming.
  • Added support for the AFM module for Telemetry Streaming.
  • Added the Intrusion Detection Data Model for ASM module events.
  • The events for the f5:bigip:gtm:dns:response:irule source type will be mapped to the Network DNS Resolution Data Model.
  • Removed the support for partitions from the Server Configuration.
  • The data collected using the SOAP API will be parsable and searchable, but the user will no longer be able to collect the data using the SOAP API.

Upgrade Guide

The Splunk add-on for F5 BigIP version 6.0.0 collects the data using Telemetry Streaming. If you configured any custom template to collect the data from the SOAP API, you will need to locate the REST API replacement for that SOAP API, to perform the data collection using the new version of this add-on. For more information, see Create New Templates.

  • You will need to reconfigure the inputs to start the data collection. For more information on creating inputs for this add-on, see Create Inputs.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Add-on comparison

Splunk Add-on for F5 BIG-IP 5.1.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 8.0+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 6.0.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 6.0.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Some of the components included in this add-on are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for this add-on is available as a PDF file for download: Splunk Add-on for F5 BIG-IP third-party software credits

Version 5.1.0

Version 5.1.0 of the Splunk Add-on for F5 BIG-IP was released on July 12, 2021.

Compatibility

Version 5.1.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.0.x, 8.1.x, 8.2.x
CIM 4.18.1
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 15.1.0 Licensed LTM, DNS (GTM), APM, and ASM modules.

New Features

  • Fast and intuitive UI with a better look and feel.
  • Provides critical security fix by removing jquery2.
  • Removal of python2 support. Only python3 is supported from now on.
  • Fixed issue where a server error stopped data collection.

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 3.0.0 or later, data is collected by default from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 Servers page (Configuration > Server) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Splunk Add-on for F5 BIG-IP 5.1.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 8.0+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 5.1.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 5.1.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Version 5.1.0 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.

Version 5.0.0

Version 5.0.0 of the Splunk Add-on for F5 BIG-IP was released on March 18, 2021.

Compatibility

Version 5.0.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.3.x, 8.0.x, 8.1.x
CIM 4.18.1
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 15.1.0 Licensed LTM, DNS (GTM), APM, and ASM modules.

New Features

  • The UI of the AddOn has been migrated to the UCC framework.
  • The user will now be able to configure logging from the UI.
  • The passwords, templates, servers and tasks configured by the existing users will be automatically migrated to the latest version of the AddOn.
  • The data from the f5_bigip_tasks.conf, f5_bigip_templates.conf and f5_bigip_servers.conf files will be migrated to inputs.conf, f5_templates.conf, f5_servers.conf files respectively.
  • For migrating the stanzas from the f5_bigip_tasks.conf, f5_bigip_servers.conf, f5_bigip_templates.conf files, the data in these files will remain intact. The data from these conf files will be migrated to the new conf files and these files will be referred for data collection.
  • Support for Destination App for servers, templates, and inputs has been removed from the latest version of the AddOn.
  • For each input, separate process will be spawn, hence the CPU Utilization will be improved

Additional Release Notes

  • The data collection logs will be logged under Splunk_TA_f5_bigip_main.log file. The user can find the log file under $SPLUNK_HOME$/var/log/splunk
  • The logs for the migration scripts like migrate_existing_inputs, migrate_existing_passwords, migrate_existing_templates will be logged under migrate_existing_inputs.log, migrate_existing_passwords.log, migrate_existing_templates.log respectively. The user can find the log files under $SPLUNK_HOME$/var/log/splunk

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 3.0.0 or later, data is collected by default from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 Servers page (Configuration > Server) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Splunk Add-on for F5 BIG-IP 5.0.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 7.3+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 5.0.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 5.0.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Version 5.0.0 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.

Version 4.0.1

Version 4.0.1 of the Splunk Add-on for F5 BIG-IP was released on October 13, 2020.

Compatibility

Version 4.0.1 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.2.x, 7.3.x, 8.0.x
CIM 4.17
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 15.1.0 Licensed LTM, DNS (GTM), APM, and ASM modules.

New Features

  • Migrated for the new data collection mechanism for Telemetry streaming available for F5 BIG-IP version 13.1 and later.
  • Added support for the new AVR event type.
  • Improved support for Splunk Connect for Syslog.

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 3.0.0 or later, data is collected by default from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 BIG-IP Servers page (Configurations > Servers) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Splunk Add-on for F5 BIG-IP 4.0.1 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 7.2+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 4.0.1 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 4.0.1 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Version 4.0.1 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.

Release notes for the Splunk Add-on for F5 BIG-IP Version 3.1.0

Version 3.1.0 of the Splunk Add-on for F5 BIG-IP was released on April 16, 2020.

Compatibility

Version 3.1.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.2.x, 7.3.x, 8.0.x
CIM 4.15
Platforms Platform independent
Vendor Products F5 BIG-IP F5 BIG-IP 11.6.5 - 15.1.0 Licensed LTM, DNS (GTM), APM, and ASM modules.

New Features

  • Support for Python 3 by default
  • FIPS Certification
  • Support through v15.1.0 of F5 BIG-IP

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 3.0.0 or later, data is collected by default from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 BIG-IP Servers page (Configurations > Servers) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Splunk Add-on for F5 BIG-IP 3.1.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 7.2+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 3.1.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 3.1.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Version 3.1.0 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.

Version 3.0.0

Version 3.0.0 of the Splunk Add-on for F5 BIG-IP was released on October 21, 2019.

Compatibility

Version 3.0.0 of the Splunk Add-on for F5 BIG-IP is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 7.0.x, 7.1.x, 7.2.x, 7.3.x, 8.0.x
CIM 4.12
Platforms Platform independent
Vendor Products F5 BIG-IP 10.1 - 12.X. Licensed LTM, DNS (GTM), APM, and ASM modules.

Versions 2.7.0 and earlier of the Splunk Add-on for F5 BIG-IP are incompatible with versions 8.0 and later of the Splunk platform.

Upgrade guide

If you are upgrading from the Splunk Add-on for F5 BIG-IP 2.2.0 or earlier to the Splunk Add-on for F5 BIG-IP 2.3.0 or later, note that version 2.2.0 and earlier collected data from the Common partition only. After you upgrade to version 3.0.0, by default data will be collected from all of the partitions on the F5 BIG-IP servers that are configured for data collection. You can change this by editing your existing server configuration on the Manage F5 BIG-IP Servers page (Configurations > Servers) and updating the Partitions field. If you want to continue to collect data from only the Common partition, type Common in this field and click Update.

Migration from other add-ons

There is no migration path for the other add-ons on Splunkbase to the Splunk Add-on for F5 BIG-IP.

The Splunk Add-on for F5 BIG-IP is a Splunk supported add-on for the LTM, GTM, APM, and ASM BIG-IP modules. It does not replace existing add-ons on Splunkbase that collect data from F5 devices.

You can install the Splunk Add-on for F5 BIG-IP into an existing Splunk platform deployment that has the other add-ons installed, as long as the add-ons do not share the same port or source types.

Splunk Add-on for F5 BIG-IP 3.0.0 Splunk for F5 Access Splunk for F5 Networks Splunk for F5 Security
Sourcetype See the source types topic for a full list syslog No default source type No default source type
Domain LTM, GTM, APM, ASM APM, FirePass LTM, AFM ASM, APM
Port 9514/9515 514 No default port No default port
Splunk platform version 6.5+ 4.0 to 6.0 4.0 to 6.0 4.0 to 6.0

Fixed issues

Version 3.0.0 of the Splunk Add-on for F5 BIG-IP has the following fixed issues:

Known issues

Version 3.0.0 of the Splunk Add-on for F5 BIG-IP has the following reported known issues. If no issues appear below, no issues have yet been reported:

Third-party software attributions

Version 3.0.0 of the Splunk Add-on for F5 BIG-IP incorporates the following third-party software or libraries.