Forum Discussion

F5_Jeff's avatar
F5_Jeff
Icon for Cirrus rankCirrus
Oct 06, 2016

F5 ASM and Arcsight Integration

Good day everyone!

 

We are planning on integrating the Arcsight SIEM to F5 ASM.

 

Does anyone know what is the minimum EPS to send logs to the Arcsight.

 

An article will be very helpful.

 

Thank you!

 

1 Reply

  • It depends on what you want to log (All Requests or Violations Only). In Production environments it is recommended to log only the Violations if EPS is an issue. How many EPS really depends on how frequently your application is attacked and many violations per second are being logged and whether you have applied any filters (you can choose what to log!). EPS can be 1 in normal use and can be 1000 or more during a DDOS attack.

     

    Here is the Configuring Application Security Event Logging manual:

     

    https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/asm-implementations-11-5-0/12.html