Forum Discussion
IP-Intelligence logs not pushed to SIEM(splunk)
Hi,
is there a possibility to send the IP-Intelligence log to a SIEM product (splunk)? Within the F5-iApp ( https://www.f5.com/pdf/deployment-guides/f5-analytics-dg.pdf ) we don't see the IP-Intelligence log information, but there are definitly logs available within the f5-GUI?
Is there anything special/rule/..-setting necesssary we can activate, that this logs are also pushed to central SIEM solution?
Best Regards Martin
- CharlesCS
Cirrus
On a per-virtual server basis, you will need to assign a logging profile which has Network Firewall enabled, and the IP Intelligence publisher set to your SIEM publisher. Note that none of the system-provided logging profiles are configured in this manner, so you will need to create a custom logging profile.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com