Forum Discussion
CEF logs F5
- Feb 18, 2025
Hi,
After doing further research it looks like the ArcSight log format is only supported for AFM, ASM and SWG logs (and not system logs) which is why you do not see the option (as I assume you do not have any of these modules provisioned on your BIG-IP)ArcSight logging destination / ArcSight CEF format is only supported for modules AFM, ASM, and SWG components.
Kind regards,
Michael
Hi,
This is possible. You will just need to configure it slightly differently using HSL (High Speed Logging).
A high level overview of what you would need to configure:
1) An LTM pool of remote syslog server(s) (e.g. 192.168.1.123:514)
2) A Log Destination referencing the LTM pool (System > Logs > Configuration > Log Destinations > Create)
In the "Type" dropdown menu, select "ArcSight" (which is CEF format)
3) A Log Publisher referencing the Log Destination (System > Logs > Configuration > Log Publishers > Create
More detailed instructions below:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com