Forum Discussion
lee9926
Nimbostratus
Aug 16, 2026F5 ASM remote logging format (Splunk KV pairs)
Hi, I had referred to F5 resource for the details about the fields found in the ASM logs (f5 AWAF). However, it seem like it doesn't have the full details of every fields found in the logs. Do we hav...
mwolf
Nimbostratus
Aug 23, 2026The basic answers can be found in
Event Messages and Attack Types
and
K9435: Overview of the Storage Format option for a remote logging profile
date_time - Yes, this should be the timestamp of when ASM processed the request.
- violation_rating - K000137152: Violation Rating Based Enforcement
- route_domain - This is a BIG-IP LTM route domain.
- syslog_priority - This part of the syslog protocol. RFC 5424 Section 6.2.1 "The number contained within these angle brackets is known as the Priority value (PRIVAL) and represents both the Facility and Severity.
- sig_ids, sig_names, staged_sig_ids, staged_sig_names, sig_cves, staged_sig_cves - Event Messages and Attack Types
- ip_address_intelligence - Enabling IP Address Intelligence
websocket_direction, websocket_message_type - Yes they are details for the websocket protocol.
threat_campaign_names, staged_threat_campaign_names - Managing Threat Campaigns
- blocking_exception_reason - It's a reason why an illegal request was not blocked.
- microservice - ASM attempting to match the request to the micro service configured on the ASM policy.
- tap_event_id, tap_vid - TAP is short for threat analysis platform,
- fragment - It's the query string is the URL when the # separator is used.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects