Forum Discussion

ArieYank_342073's avatar
ArieYank_342073
Icon for Nimbostratus rankNimbostratus
Jan 22, 2018

Send Command Audit log to TACACS+

Hi, I'm new in F5 Technology. I have setup lab testing to test TACACS+ AAA between F5 and Cisco ISE. Below is the F5 in lab environment: Product BIG-IP Version 12.1.2 Build 0.0.249 Edition Final

 

The Authentication and Authorization have worked successfully. For Accounting, I have issue with view audit log in TACACS+ server. In BIG-IP web GUI, I can see the audit log by navigating to System > Logs > Audit > List. I can see the commands that executed by the user. I follow the configuration guide from: https://support.f5.com/csp/article/K13762 But in TACACS+ server, it doesn't receive any audit log which contain executed commands. I only see the Accounting Interim Update from F5 to TACACS+ server. Is there any missing configuration in F5 BIG-IP system to send executed commands log to TACACS+ server?

 

Thank you

 

Arie