Forum Discussion
DoS dont send Syslog to Remote Highspeed logging server
Hello,
Anyone have issues with Remote High-Speed loging server and l4 DoS Sylog?
I have created under Security > Event Logs > Logging Profiles > RemoteLog > here I enable DoS Protection and I enabled network Firewall & DoS Protection with Local & Remote Publisher enabled. Application Security use Remote Storage > This works.
For Remote Publisher I create pool (same port & same server as for Application Security) and attached (tried with both ArcSight & Splunk) to Remote destination where I chose Pool server. Using tcpdump I only see Application Security Events but don’t see DoS started Syslog msg (in Web UI I see Dos started, I also get SNMP Alarm) , also I don’t get Network Firewall events like reject, accept (put this for test), …. Anyone have same issue?
2 Replies
- Tikka_Nagi_1315Historic F5 Account
What version of the AFM are you using? Do you see Dos started/Stopped messages in /var/log/ltm?
- jban_198207
Cirrus
Hi,
Yes, in /var/log/ltm I have Jun 16 13:24:48 hostname err tmm[22308]: 01010252:3: A NETWORK /PARTITION/VSERVER_POLICY DOS attack start was detected for vector TCP SYN flood, Attack ID 1869164187.
Version: 12.1.0 0.0.1434
SNMP Trap also sent, but not Syslog.
Also this new version do not write Brute Force detection under Events.
All this with Syslog, SNTMP Traps, Event logging is a bit ...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com