How to view logs with source and destination ip address.
We are running Bigip v11.4.1 Build 647.0 Hotfix HF4. We have some VIPs that we want to decommission. We need to know which ip address' are still trying to connect to these VIPs. I created an irule that logs ([serverside {TCP::local_port}] dst [IP::server_addr]:[TCP::server_port]) and assigned it to these VIPs. This works and I am able to view the source ip alongside the destination ip address.
However, anytime I am asked to do this, I have to assign the irule to a specific VIP and wait for the VIP to get hit. Does the F5 log this information somewhere by default? Or is there a setting to enable this logging for all VIPs? I'm thinking that doing this would cause performance issues on the F5. If not, please let me know how I can enable this.
However, if this is not a good idea, can someone advise me on how I can get history (1 day/week/month, etc) of source/destination ip address' that connected to any VIP? Without having to apply an irule and wait for the data to collect?
Please note. I have remote logging enabled to our syslog server.