Forum Discussion
ASM logs to SIEM
currently f5 system logs are forwarded to mcafee siem, now ASM profiles are enabled and how to identify if the asm logs are also forwarded to siem. any tcpdump to identify asm logs being forwarded.
- Jinshu
Cirrus
You can use tcpdump to see if syslog messages are forwarding but you wont be able to read the contents unless open it in tools like wireshark and do a packet inspection.
I would suggest to look at it in the syslog server if you are receiving the ASM logs with a tag 'ASM' at the start.
-Jinshu
- PeteWhite
Employee
Make sure that the SIEM is available on the TMM side ie not via the management interface. Do a tcpdump to check whether the traffic is being sent to the SIEM, make sure your SIEM has plenty of power - it's very easy to crash the SIEM server with a BIG-IP.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com