I'm running AFM on my LTM v12.1.2. I only have a Global policy and configured the logging profile "global-network" to use the "local-db-publisher". Under the "Stroage Format" option, I've selected all available items. Lastly, I've verified that Network Firewall events are being generated.
I've looked at the /var/log/ltm file but did not see anything that looks like firewall event logs.
I'm trying to find where the the Network Firewall event logs are being stored on the LTM itself. (ie. sub-directory and file name) I wish export the Network Firewall even log file to my laptop.
You have to enable logging to syslog on the log-publisher, to be able to view the logs in CLI.
The logs will then be located under /var/log/ltm after enabling logging to syslog.
See screenshot below: