Forum Discussion
No IP Address observe in logs
Hi,
for information you don't have source IP user in audit logs.
you have the following info in this logs:
- Timestamp: The time and date that the system logged the event message.
- User Name: The name of the user who made the configuration change
- Transaction ID: the identification number of the configuration change.
- Event: A description of the configuration change that caused the system to log the message.
So you don't have the source IP of the user in the audit logs and you cant' set it.
So it's why F5 and best practice preconise us to set nominative identifiers. I advise you to change admin and root password then create a specific users for each user (you can use external auth: ldap, radius, ad, ldap...). It will allowed you to avoir this kind of problem...
For you problem you can check when the user was created then connect in CLI and check secure logs.
/var/logs/secure
and during this period look at the IPs of the users who are authenticating with the administrator account.
Hope it help you.
regards
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
