Bug ID 665700: APM 11.x upgrade breaks 'log only message-id' workflow

Last Modified: Oct 17, 2023

Affected Product(s):
BIG-IP APM, Install/Upgrade(all modules)

Known Affected Versions:
12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2

Opened: May 19, 2017

Severity: 3-Major

Symptoms

After upgrading from APM 11.x, if you have the following filter in your config, it is ignored: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher /Common/HSL_Splunk source accesscontrol } In this case, the admin user will no longer get HSL messages of type 01490143. The only thing the filter is able do is negative filtering: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher none source accesscontrol } In this case, specifying publisher 'none' still drops log entries, so you can use this filter to send everything except message-id 01490143, but the previous workflow of sending only message-id 01490143 no longer works.

Impact

The previous workflow of sending only message-id 01490143 no longer works.

Conditions

-- Upgrading from 11.x. -- the log-config filter in 11.x is configured to filter only for message-id 01490143, for example: sys log-config filter /Common/HSL_Splunk { level notice message-id 01490143 publisher /Common/HSL_Splunk source accesscontrol } sys log-config publisher /Common/HSL_Splunk { destinations { /Common/HSL_Splunk { } } } sys log-config destination remote-high-speed-log /Common/HSL_Splunk { pool-name /Common/HSL_Splunk protocol udp } -- Upgrading to 12.x or 13.x.

Workaround

None.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips