LTM Log Files

I need to be able to see tcp traffic between client and F5 and between F5 and pool memebers. Anybody knows how I can setup and view that? Thanks

if you have cli access, you can use tcpdump. You can specify a file for clientside/serverside separately or you can use the special interface 0.0 to capture from all links.

by default, system log (e.g. /var/log/ltm) does not include application traffic. if you want to log application traffic, you can use irule.

e.g.

Log Http Tcp Udp To Syslogng

DevCentral - An F5 Technical Community

by default, system log (e.g. /var/log/ltm) does not include application traffic. if you want to log application traffic, you can use irule.

e.g.

Log Http Tcp Udp To Syslogng

DevCentral - An F5 Technical Community

Hi Nitaas, Can’t i see tcp traffic between client and F5 and between F5 and pool memebers from F5 LTM cli??? If yes can you please shrae the commands to check it.

Hi Nitaas, Can’t i see tcp traffic between client and F5 and between F5 and pool memebers from F5 LTM cli??? If yes can you please shrae the commands to check it.

do yo mean packet? if yes, you can run tcpdump. tcpdump -nni 0.0 -s0 host x.x.x.x or host y.y.y.y x.x.x.x is client ip y.y.y.y is pool member ip

do yo mean packet? if yes, you can run tcpdump. tcpdump -nni 0.0 -s0 host x.x.x.x or host y.y.y.y x.x.x.x is client ip y.y.y.y is pool member ip

(more tcpdump info) - 404 Page not found | BIG-IP Documentation There is also the command “tmsh show sys connection” which will show you current connection details

(more tcpdump info) - 404 Page not found | BIG-IP Documentation There is also the command “tmsh show sys connection” which will show you current connection details

You can capture client side traffic and responding server side traffic using below command::

tcpdump -vvnni 0.0:nnnp -s0 host x.x.x.x and port yy

  • where x.x.x.x is Virtual IP and yy is virtual server port number

If you want to traffic for a specific client then::

tcpdump -vvnni 0.0:nnnp -s0 host x.x.x.x

  • where x.x.x.x is client IP

If you want write captured traffic to a file to review later in wire shark or some other tool use ‘w’ option and provide path to the file

tcpdump -vvnni 0.0:nnnp -s0 -w /var/tmp/capture.pcap host x.x.x.x