Forum Discussion
boneyard
Aug 22, 2017MVP
perhaps already solved, if not this might be useful.
what is your APM logging profile currently? check at Access Policy ›› Access Profiles : Access Profiles List: Logs (last tab).
you can create a new logging profile with more logging turned on. if splunk just receives the APM log data you should get more, i see for example in that log file
Aug 22 20:05:09 bigip-01 info apmd[19436]: 01490007:6: /Common/ap:Common:c3356c01: Session variable 'session.logon.last.username' set to 'test'