Forum Discussion
[Reporting - Chart for monthly]
Dear All,
Currently, we just deploy a F5 ASM Firewall into our network. It's running on BIG-IP 11.2.1 Build 862.0 Hotfix HF2. The F5 ASM also integrates with Splunk. All the illegal request will log to Splunk. I'm having some issues generating a monthly report (Top attacker for blockeed request) using the built in feature provided by F5. When I'm trying to generate a report for a month i will only show 2 weeks. Is there a configuration i require to change for me to get a monthly report? FYI, i prefer report generating from F5 rather than Splunk
Thanks
4 Replies
you mean with a report that you use Charts? and you have set it to Time Period: Month? could be the F5 has already cycled the information, when you search on events how far back can you go?
- brandon_liew_ch
Nimbostratus
Yes, u r right. Only cycle for a month. Example, Let say from 11 August 2013 - 11 September 2013 The maximum data i am able to get is only 1 week plus to 2 weeks
if you extend the period you will probably see there simply is no data for the first part of the period. the ASM only keeps the data upto a certain point and then deletes it to keep enough space available.
I understand you want to use the ASM for this but ASM is not meant as a reporting device. personally i would expect you could get much better data with Splunk, but im not that familiar with it.
- brandon_liew_ch
Nimbostratus
Agree with you. But I'm trying to integrate with Splunk but having problem grabbing the logs.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com