Forum Discussion
LTM Logs to Remote Arcsight Server
I'm trying to setup my Big IP v12.1.1 to send the LTM logs (/var/log/ltm) to a remote arcsight server using the CEF format.
I've got it setup to send security logs to the remote server using the CEF format, but cannot figure out how to send the LTM logs.
Any ideas on where to start?
4 Replies
- YossiV
Nimbostratus
you need to use it as HSL https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-external-monitoring-implementations-11-3-0/2.html and than you have log filter, you can choose what to forward to the logger
- msmith1356_2932
Nimbostratus
This article is stated to apply to version 11.3...i'm assuming there will be no change when working with v12.1.1?
- YossiV
Nimbostratus
i am with 12.1.1 same working same way
- writemike
Nimbostratus
Try this one: Manual Chapter: Configuring Remote High-Speed Logging
If the only module you have provisioned is LTM, then you will need to look at using an iRule to do HSL Logging.
Intermediate iRules: High Speed Logging - Spray Those Log Statements!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com