Forum Discussion
Greg_130338
Aug 18, 2015Nimbostratus
Syslog to McAfee SIEM
Anyone integrate LTM and APM logging with a McAfee SIEM receiever (or any syslog receiver for that matter)? I am configuring I have the remote logging server configured in my log settings on the devi...
SDnath_82757
Aug 21, 2015Nimbostratus
Even i am trying to integrate. Currently we see the log in McAfee ESM as unknown. McAfee says no issue at there end. If you have successfully integrated, please share some pointers.
- Greg_130338Aug 21, 2015NimbostratusThe erc has device types for ltm apm and asm but all the rules apply to each one. So i just added my bigip internal ip address as a data source, enabled logging on ltm in system config and moved the default logging profile over from available on each apm policy. That seemed to capture and parse everything. What are your versions on bigip and esm?
- Greg_130338Aug 21, 2015NimbostratusSorry i neant i just added bigip internal ip as f5 ltm and it encompassed all ltm apm and asm parsers
- SDnath_82757Aug 24, 2015NimbostratusIs that the SIEM default F5 parsing rules were able to get the logs parsed. Is that all type of logs were visible to the Mcafee Siem
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects