Forum Discussion
hooleylist
Aug 18, 2011Cirrostratus
Hi Dan,
You could potentially do this using the ASM_RESPONSE_VIOLATION iRule event (v10.1.0+). You'd want to have the illegal status in response marked for alarming, but not blocking.
http://devcentral.f5.com/wiki/iRules.ASM_RESPONSE_VIOLATION.ashx
You can then use ASM::payload to get the current app payload.
Aaron