Forum Discussion

Aaron_Chandra_3's avatar
Aaron_Chandra_3
Icon for Nimbostratus rankNimbostratus
Feb 20, 2017

ASM (11.6.0) policy doesn't log

Hi,

 

i have imported a ASM policy from my lower environment to prod Version (both 11.6.0), after the policy update prod asm doesn't log anything in the event logs.i can see only the log prior to the update. It was working fine before. any thoughts to fix this?

 

2 Replies

  • if the asm policy has been moved to a new virtual server, make sure the correct logging profile is attached. it can be found on the policies tab on the virtual server.

     

  • From BIG-IP ASM 11.6 onward, F5 system no longer writes security events to syslog by default. So it does not log them locally to the /var/log/asm. You may enable the send_content_events parameter to bring back the logs. However F5 dont recommend to enable this. What you can do is to send the logs to remote logging server. https://support.f5.com/csp/article/K16053