For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Anzine321's avatar
Anzine321
Icon for Cirrus rankCirrus
Jul 08, 2025
Solved

routing to splunk for asm logging

Hi

is it possible route to splunk via management not selfip ? what is pro and cons ?

if i have partition with route domain and should use self ip, should i used in commond partition or specific partition ?

  • Hi Anzine321​ 

    Yes, it is possible to send ASM (Application Security Manager) logs to Splunk via the management interface.

    Refer below article:

    K30729139: Sending BIG-IP logs to a specific Syslog server, via the BIG-IP's management interface

    Pros: It keeps logging traffic separate from production/data traffic.

    Cons: Management interface may have limited bandwidth and Not suitable for high-volume logging in large environments

     

     

2 Replies

  • VGF5's avatar
    VGF5
    Icon for Cumulonimbus rankCumulonimbus

    Hi Anzine321​ 

    Yes, it is possible to send ASM (Application Security Manager) logs to Splunk via the management interface.

    Refer below article:

    K30729139: Sending BIG-IP logs to a specific Syslog server, via the BIG-IP's management interface

    Pros: It keeps logging traffic separate from production/data traffic.

    Cons: Management interface may have limited bandwidth and Not suitable for high-volume logging in large environments

     

     

  • Yes it is possible.

    You simply need to add a management route for your syslog server and allow the traffic in any firewall in between.