Forum Discussion
What is the best log Log Analysis Tool for F5 AFM/APM?
At the moment we use Graylog as a Log Analysis Tool. But we are not happy with it.
Very difficult to install and to maintain when you are not a linux freak. After updating our Linux System Graylog isn't working anymore.
Best solution would be an appliance.
any advice?
If you have many F5 devices, you may consider using the F5 BIG-IQ central managment platform as it can collect statistics and manage many F5 devices with all their modules like AFM/APM. BIG-IQ with DCD can monitor your LTM/APM. There is a trial version of BIG-IQ or you can ask the F5 sales for a Demo to see if it is what you want and need
Other options that were already mentioned to you are SIEM solutions like QRadar or Splunk but for a small company ELK is also an option as there is a free option and if you want vendor support then you pay for it. With the SIEM solutions you may need to build dashboards for AFM and APM as F5 has pluggins for most SIEM solution but primary for LTM/ASM(AWAF) and BIG-IQ already has prebuild dashboard.
https://www.elastic.co/guide/en/welcome-to-elastic/current/getting-started-guides.html
https://www.elastic.co/security/siem
Hi Netztester ,
What about using Qradar or Splunk ?
it’s an easy deployed monitoring and log analysis solutions and I think both of them is the most effective.If you have many F5 devices, you may consider using the F5 BIG-IQ central managment platform as it can collect statistics and manage many F5 devices with all their modules like AFM/APM. BIG-IQ with DCD can monitor your LTM/APM. There is a trial version of BIG-IQ or you can ask the F5 sales for a Demo to see if it is what you want and need
Other options that were already mentioned to you are SIEM solutions like QRadar or Splunk but for a small company ELK is also an option as there is a free option and if you want vendor support then you pay for it. With the SIEM solutions you may need to build dashboards for AFM and APM as F5 has pluggins for most SIEM solution but primary for LTM/ASM(AWAF) and BIG-IQ already has prebuild dashboard.
https://www.elastic.co/guide/en/welcome-to-elastic/current/getting-started-guides.html
https://www.elastic.co/security/siem
- RedWave25Nimbostratus
For anybody reading this don't waste your time with BIG IQ. It's not capable of any alerting. No custom alerts, no nothing. F5 says to use third party if you want to know when a member of your pool is down.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com