Forum Discussion
ASM Logs Override
Hi All, I'm trying to cut down on the amount of logs we sent through from ASM to our SIEM (LogRhythm - if anyone has any tips/help on log policies that'd be great, it's pretty rubbish out of the box)
Majority of ASM logs are for Attack Type "Non Browser Client" or specific URL's such as "/wp-login.php" and exchange autodiscovers... which i just dont need to log or report on.
Any way for me to drop these in ASM before they appear in the logs and get syslog'd to SIEM? An iRule perhaps ?
1 Reply
- Leonardo_Souza
Cirrocumulus
I had a look in the logging profiles, but does not look like you can do this with the log profile. However, you can do that in the syslog itself. You can apply a filter for those messages you don't want to see the logs, and it will not be sent to your server.
see this solution for more information:
https://support.f5.com/csp/article/K13333
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com