Forum Discussion
F5 ASM logs : Passwords appear in clear text
We have syslog servers configured. We recently observed that on ASM requests logs that are being forwarded to syslog servers, the password parameter value is given in clear text on the /owa/auth requests.
I observed that mostly the requests which get blocked have the values being displayed in clear text. while genuine traffic requests have the same values sanitized/encrypted.
The parameters mentioned are already given as sensitive parameters in the policy.
Need to know if this is normal behaviour for F5
Thanks,
Arjun
- Dario_Garrido
Noctilucent
Hello.
I recommend you to check this ->
https://devcentral.f5.com/s/question/0D51T00006j3Rwg/asm-hide-parameter-sensitive-data-in-the-logs
Let us know if it doesn't help.
KR,
Dario.
- Dario_Garrido
Noctilucent
- Arjun
Nimbostratus
Hi Dario, Thank you for the reference links. I am currently running the version 13.1.1 and the option mentioned in the F5 Article is not available yet. Moreover already we have sensitive data enabled and the URL with the parameter is having "Request Body Handling" to Form DATA.
Is there anything else we need to check.
- Dario_Garrido
Noctilucent
Try to open a support case.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com