Forum Discussion

MLiebelt_321846's avatar
MLiebelt_321846
Icon for Nimbostratus rankNimbostratus
May 24, 2017

IP-Intelligence logs not pushed to SIEM(splunk)

Hi,

 

is there a possibility to send the IP-Intelligence log to a SIEM product (splunk)? Within the F5-iApp ( https://www.f5.com/pdf/deployment-guides/f5-analytics-dg.pdf ) we don't see the IP-Intelligence log information, but there are definitly logs available within the f5-GUI?

 

Is there anything special/rule/..-setting necesssary we can activate, that this logs are also pushed to central SIEM solution?

 

Best Regards Martin

 

1 Reply

  • On a per-virtual server basis, you will need to assign a logging profile which has Network Firewall enabled, and the IP Intelligence publisher set to your SIEM publisher. Note that none of the system-provided logging profiles are configured in this manner, so you will need to create a custom logging profile.