Forum Discussion

Ahmed_Galal's avatar
Ahmed_Galal
Icon for Cirrostratus rankCirrostratus
Oct 07, 2019
Solved

Splunk syslog loadbalancing

Hi All,

 

i have 2 Splunk Syslog server using UDP 514, splunk configure incoming logs upon source ip address so when i configured to load balance servers through F5 with automap it created one log file for all devices is there any solution can do X-Forward for UDP traffic in F5.

  • Hi

     

    As syslog is fire and forget in nature, you probably don't need to use SNAT as there is no need for a return path. Try disabling SNAT on your VIP in the first instance.

2 Replies

  • Hi

     

    As syslog is fire and forget in nature, you probably don't need to use SNAT as there is no need for a return path. Try disabling SNAT on your VIP in the first instance.

    • Ahmed_Galal's avatar
      Ahmed_Galal
      Icon for Cirrostratus rankCirrostratus

      i configure it without SNAT but am facing issue now that firewall detecting that traffic connecting from diffrant zone do you have anything in mind ??