Forum Discussion
Configuring Syslog Server for a Specific Virtual Server
- Oct 03, 2017
Greetings,
I haven't used the virtual server's Request Logging profile much, but was able to create a profile that logs the source IP address of the connecting client:
In the Request profile Template section, I simply entered:
Client IP is: ${CLIENT_IP}
And it was sent to the remote syslog:
14:10:53.969588 IP 10.12.23.120.48392 > 10.12.23.27.514: [|syslog] 0x0000: 4500 0037 cb69 4000 ff11 6da1 0a0c 1778 E..7.i@...m....x 0x0010: 0a0c 171b bd08 0202 0023 7989 436c 6965 .........y.Clie 0x0020: 6e74 2049 5020 6973 3a20 3130 2e31 322e nt.IP.is:.10.12. 0x0030: 3235 302e 3133 30 250.130
Hope this is useful!
Kevin
Greetings,
I haven't used the virtual server's Request Logging profile much, but was able to create a profile that logs the source IP address of the connecting client:
In the Request profile Template section, I simply entered:
Client IP is: ${CLIENT_IP}
And it was sent to the remote syslog:
14:10:53.969588 IP 10.12.23.120.48392 > 10.12.23.27.514: [|syslog]
0x0000: 4500 0037 cb69 4000 ff11 6da1 0a0c 1778 E..7.i@...m....x
0x0010: 0a0c 171b bd08 0202 0023 7989 436c 6965 .........y.Clie
0x0020: 6e74 2049 5020 6973 3a20 3130 2e31 322e nt.IP.is:.10.12.
0x0030: 3235 302e 3133 30 250.130
Hope this is useful!
Kevin
Hi, kevin
I configured the profile "request logging".
The problem I'm having is that on the production ssyslog (Linux) server the access information does not appear.
I installed a syslog program on my computer for testing (3CDaemon program) and in this case the access information appeared correctly.
It seems that BIG-IP forwards this information to a "user.info" facility, and this facility is what does not appear on the production syslog server.
You would have to see a way for this information to be routed to some "local (1-6) location on the production syslog server."
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com