Loading...
Loading...
After upgrading from APM 11.x, if you have the following filter in your config, it is ignored: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher /Common/HSL_Splunk source accesscontrol } In this case, the admin user will no longer get HSL messages of type 01490143. The only thing the filter is able do is negative filtering: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher none source accesscontrol } In this case, specifying publisher 'none' still drops log entries, so you can use this filter to send everything except message-id 01490143, but the previous workflow of sending only message-id 01490143 no longer works.
The previous workflow of sending only message-id 01490143 no longer works.
-- Upgrading from 11.x. -- the log-config filter in 11.x is configured to filter only for message-id 01490143, for example: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher /Common/HSL_Splunk source accesscontrol } sys log-config publisher /Common/HSL_Splunk { destinations { /Common/HSL_Splunk { } } } sys log-config destination remote-high-speed-log /Common/HSL_Splunk { pool-name /Common/HSL_Splunk protocol udp } -- Upgrading to 12.x or 13.x.
None.
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.