Skip to content

feat(generator): multi-product F5 log generator (PIPE-1027, BP-473) - #323

Open
Dylan-M wants to merge 1 commit into
mainfrom
dylanmyers/pipe-1027-f5-multi-product-log-generator-big-ip-family-nginx-on-f5
Open

Dylan-M wants to merge 1 commit into
mainfrom
dylanmyers/pipe-1027-f5-multi-product-log-generator-big-ip-family-nginx-on-f5

Conversation

@Dylan-M

@Dylan-M Dylan-M commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Proposed Change

Multi-product F5 log generator spanning the BIG-IP modules, NGINX-on-F5, iRules, and F5OS. F5 logging is largely operator-defined, so fidelity splits two ways:

  • Where F5 publishes a fixed default format, output is byte-exact to it, order-asserted: NGINX App Protect, ASM, AFM, NGINX Plus, audit.
  • Where logging is operator-defined with no positional spec, output follows F5's documented default profile without claiming byte-exactness: LTM, APM, DNS, iRules, F5OS.
Checklist
  • Changes are tested
  • CI has passed

@Dylan-M
Dylan-M requested review from a team as code owners September 25, 2026 15:25
NewOverride("generator.count", "total number of logs to generate (0 = unlimited)", 0),
NewOverride("onFinish", "behavior when finite generation completes. One of: exit|idle", "exit"),
NewOverride("generator.type", "generator type. One of: nop|json|winevt|wel|palo-alto|apache-common|apache-combined|apache-error|nginx|postgres|kubernetes|filegen|okta|hostmetrics|traces", GeneratorTypeNop),
NewOverride("generator.type", "generator type. One of: nop|json|winevt|wel|palo-alto|apache-common|apache-combined|apache-error|nginx|postgres|kubernetes|filegen|okta|hostmetrics|traces|fix|f5", GeneratorTypeNop),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are no generator.f5.* overrides, so the BLITZ_GENERATOR_F5_* env vars and CLI flags are never bound. The blitz-f5 compose service fails with f5 generator workers must be 1 or greater, got 0, and --generator-f5-workers gives unknown flag. Only YAML works. Also, an unset seed comes through as 0, not DefaultConfig's -1, so every run produces the same records.

Comment thread generator/f5/f5.go
// buildLine picks a weighted product and builds one log line from it.
func (g *Generator) buildLine(r *rand.Rand) string {
p := g.pickProduct(r)
return p.Build(r, &catalog.Ctx{Now: time.Now(), Hostname: g.cfg.Hostname})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the syslog hostname comes from cfg.Hostname rather than the simulated identity, so it doesn't match host.name.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants