Sep 03, 2023

ASM Bot Defence logs with CEF Format

Hi all,

I have  a cluster with 2 BIG-IPs Ver and i am using the modules LTM + WAF . I found out that WAF bot defence log is with the format Syslog.My SIEM can read CEF (ArcSight) so my question is if there is a way to change the Syslog format to CEF format or if there is possibility to add a unique identifier on the syslog logs of the Bot Defense so those can be read by the SIEM.