Forum Discussion
1 Reply
- samstepCirrocumulus
Do you have 'Log All Requests' logging policy for ASM events or 'Log Illegal Requests Only'?
If you have 'Log All Requests' remember that ASM only keeps the last 100,000 requests in the internal event logs, so by the time you click on a request to investigated it may gave been already deleted as you probably already had 100,000 more requests logged in that time period (you mention one hour) .
Remember that ASM's primary function is a security device and not a logging device. In production environments it is not recommended to use 'Log All Requests' policy with local storage - instead you should ship the ASM logs to an external SIEM/logging system such as Splunk.
If you have 'Log Illegal Requests' only Logging policy and you are still frequently getting the 'deleted' error - raise a Support Case with the F5 Support team.