Forum Discussion

PowerShellDon_1's avatar
PowerShellDon_1
Icon for Nimbostratus rankNimbostratus
Feb 06, 2017

ASM Logs Override

Hi All, I'm trying to cut down on the amount of logs we sent through from ASM to our SIEM (LogRhythm - if anyone has any tips/help on log policies that'd be great, it's pretty rubbish out of the box)

 

Majority of ASM logs are for Attack Type "Non Browser Client" or specific URL's such as "/wp-login.php" and exchange autodiscovers... which i just dont need to log or report on.

 

Any way for me to drop these in ASM before they appear in the logs and get syslog'd to SIEM? An iRule perhaps ?

 

1 Reply

  • I had a look in the logging profiles, but does not look like you can do this with the log profile. However, you can do that in the syslog itself. You can apply a filter for those messages you don't want to see the logs, and it will not be sent to your server.

     

    see this solution for more information:

     

    https://support.f5.com/csp/article/K13333