For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

José_Ramón_Rodr's avatar
José_Ramón_Rodr
Icon for Nimbostratus rankNimbostratus
Mar 04, 2025

What does session_id = 0 means in ASM session tracking?

We have an ASM policy with session tracking enabled and working fine and we noticed that several ASM logs hace a session_id equals to 0. We suspected some botnet source but we don't know what it's the meaning of that zero value. How is usually got a value this parameter and why is set to zero in those cases?

1 Reply

  • José_Ramón_Rodr 

     

    I found this information for your question 

    • Requests with session_id = 0 are typically:
      • The initial request from a client before ASM sets its session cookie.
      • Requests from clients/bots that do not accept cookies or do not process JavaScript (such as some automated bots, scrapers, or privacy-focused browsers).
      • Requests where cookies have been cleared or blocked by the client.
    • ASM will only start assigning a non-zero session_id after the client has accepted the ASM cookie and/or completed the JavaScript challenge for device ID.