Forum Discussion
Logging client IP address for SSH attempts
If I may add, Kunjan is absolutely correct. The log statement in iRules sends traffic to a Syslog server. Without an IP address specified, it sends the message to the local Syslog server. You need a remote server that is running a Syslog instance and is configured to capture messages for the facilities that you're sending (ie. local0.info). Setting up a Syslog server isn't overly difficult, but can be different depending on your environment.
I would also add that HSL is a WAY better option here. Using the Log command will work, but 1) there's generally a limit to how many of those you can send out, and 2) the syslog traffic must pass through the management plane of the BIG-IP, which can induce some CPU spikes. HSL (high speed logging) is processed completely within the data plane and doesn't have the same limitations.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com