Forum Discussion
Investigation/identification of WAF Parameter violations from archived F5 ASM security logs
Hi Preet.pkm
Using Guarantee Logging will not help. When you store the logs locally, the logging utility may compete for system resources (this might be the case when you are under attack). Guarantee Logging setting ensures that the system logs the requests in this situation but may result in a performance reduction in high-volume traffic applications. However Guarantee Logging will not extend the time logs are stored locally.
Second, I would recommend enable remote logging. With two hours of local logs, you will not go anyway for.
Local logging is for analyzing what is going on right now. For forensics I recommend remote logging.
Analyzing archived logs will not make you happy on the long run.
KR
Daniel
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com