Request Logging/Log Publisher
I am having a real difficult time grasping the relationship between a log publisher, a formatted log destination and an unformatted destination. All the F5 information I can find on log publishers only gives a simple 1 sentence explanation to what a log publisher does. Is it the log publisher that formats the data into Splunk format (json) and then sends it to a formatted log destination (virtual server for Splunk) which then sends it to unformatted high speed log destination (virtual server for Splunk) wich then load-balances it to the actual splunk servers. I just don't get what is happening between the publisher, the formatted log destination and the unformatted log destination and I cannot find any expanded information on what is actually happening. I can only find 1 sentence explanations and configuration instructions. The following link has a diagram of the publisher. If anyone can explain this or point me to detailed documentation on this subject, that would be great. https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-external-monitoring-implementations-12-0-0/4.html