Forum Discussion

bsb's avatar
bsb
Icon for Nimbostratus rankNimbostratus
Mar 08, 2018

ASM logs to SIEM

currently f5 system logs are forwarded to mcafee siem, now ASM profiles are enabled and how to identify if the asm logs are also forwarded to siem. any tcpdump to identify asm logs being forwarded.

 

  • You can use tcpdump to see if syslog messages are forwarding but you wont be able to read the contents unless open it in tools like wireshark and do a packet inspection.

     

    I would suggest to look at it in the syslog server if you are receiving the ASM logs with a tag 'ASM' at the start.

     

    -Jinshu

     

  • Make sure that the SIEM is available on the TMM side ie not via the management interface. Do a tcpdump to check whether the traffic is being sent to the SIEM, make sure your SIEM has plenty of power - it's very easy to crash the SIEM server with a BIG-IP.