Forum Discussion
F5 BIG-IP DNS/Audit Logs — Structured Format for SIEM Ingestion
Hello Jeff_Granieri
Thank you for sharing the bash script.
We’ve tested it and wanted to clarify: will this script convert all types of audit logs into JSON format? For example, if we have different categories such as authentication failure (have a message fields in which it's metioned that it failed to authenticate), authentication successes, and network-related audit logs etc, will the script handle and convert each of these log types correctly into JSON?
Hi jainzeel13 ,
Its looking at /var/log/audit. You should test each audit message to confirm the script covers that you need. Feel free to make any changes to adjustments as needed.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com