Forum Discussion
Cpet
Sep 03, 2023Altocumulus
ASM Bot Defence logs with CEF Format
Hi all,
I have a cluster with 2 BIG-IPs Ver 15.1.9.1 and i am using the modules LTM + WAF . I found out that WAF bot defence log is with the format Syslog.My SIEM can read CEF (ArcSight) so my question is if there is a way to change the Syslog format to CEF format or if there is possibility to add a unique identifier on the syslog logs of the Bot Defense so those can be read by the SIEM.
Thanks
Better see this Unable to select Arcsight publisher for bot defense remote logging (f5.com) and open a RFE with the F5 Sales people.
- CpetAltocumulus
Thanks
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects