Forum Discussion
toneman
Altostratus
Nov 23, 2021ASM Event Logs - request_status = passed
I'm used to seeing event logs classified as "Illegal" or "Blocked" but in Splunk I see events that are listed as "passed" under request_status. There are obvious violations within the requests like ...
Daniel_Wolf
MVP
Nov 24, 2021Hi ,
you can refer to K9435: Overview of the Storage Format option for a remote logging profile.
The option request_status knows three different values: blocked, alerted and passed.
Maybe another setting in your security policy is missing and therefore these request are not categorized as violations? Did you apply the required Attack Signatures with the correct settings?
Is the Qualys maybe on the IP address exception list?
KR
Daniel
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects