Need to Download a Ton of F5 XC Logs in CSV? Here's a Tool for That

If you’ve worked with F5 Distributed Cloud (F5 XC) for any length of time, you’ve probably had to download logs during a troubleshooting or security investigation.

And if you’ve ever needed more than 500 logs, you’ve probably run into the same limitation I did.

The F5 XC Console provides an easy way to search and download logs, but when you need to download a large number of results, the GUI limits a single download to 500 logs.

There is an API for working with F5 XC programmatically, which provides much more flexibility. However, working directly with APIs, authentication, queries, pagination, and API responses can be a bit too advanced for many users who simply want to get their logs into a CSV file.

That’s where F5 XC Log Downloader comes in.

The Problem

Let’s say you’re troubleshooting an application issue that occurred over several hours.

You want to investigate:

  • Which requests reached the application
  • Which clients generated those requests
  • What happened to a particular URI
  • Which requests were blocked by the WAF
  • What security events occurred during the incident
  • What administrative changes happened around the same time

You search for the relevant events in the F5 XC Console and get a large result set.

Now you want to download those results. This is where things can become inconvenient.

The 500-log limitation

The F5 XC GUI allows you to download logs, but a single download is limited to 500 logs.

If your investigation requires several thousand events, you need to break the collection into multiple downloads.

For example:

3,000 logs needed >>> Download 1 → 500 >>> Download 2 → 500 >>> Download 3 → 500 >>> Download 4 → 500 >>> Download 5 → 500 >>> Download 6 → 500

That’s manageable for a small investigation, but it quickly becomes repetitive when you’re dealing with a large dataset.

But There’s an API…

F5 Distributed Cloud provides APIs that allow users to interact with the platform programmatically. This opens up significantly more possibilities for automation and data retrieval. The problem is that an API isn’t necessarily the easiest interface for everyone.

Working directly with the API can require understanding things such as:

  • API authentication
  • API tokens and certificates
  • Namespaces
  • API endpoints
  • HTTP requests
  • Request payloads
  • Query syntax
  • Pagination
  • Response structures
  • JSON processing
  • Writing or modifying scripts

For someone who works with APIs every day, that’s not particularly difficult.

For an engineer who simply needs to collect logs during a troubleshooting call, however, it can be unnecessary overhead.

I wanted something in between.

The simplicity of the GUI, with some of the flexibility of the API.

Introducing F5 XC Log Downloader

That’s why I built F5 XC Log Downloader.

It’s a standalone Windows application that provides a graphical interface for querying F5 Distributed Cloud logs through the documented APIs and exporting the results to CSV.

The basic idea is:

Use the GUI to configure your request. Let the application handle the API interaction. Get the results as CSV.

No need to write an API script for every investigation.

What Can It Download?

The application supports the three log categories.

Access / Request Logs

Useful for application troubleshooting and traffic analysis.

You can use the available query and time-range controls to focus on the traffic you’re interested in and export the results for further analysis.

Firewall / WAF Logs

Useful for security investigations, including:

  • Blocked requests
  • WAF events
  • Potential false positives
  • Repeated suspicious activity
  • Security investigations
Audit Logs

Useful for investigating administrative and configuration-related activity.

This can also help correlate configuration changes with application or security incidents.

How It Works

The workflow is intentionally simple.

Configure in GUI >>> F5 XC Log Downloader >>> F5 XC API >>> F5 Distributed Cloud >>> Retrieved Logs >>> CSV

The user doesn’t need to manually construct HTTP requests or process JSON responses.

The application handles the API communication and converts the retrieved results into a format that’s easy to work with.

A Practical Example

Imagine you’re investigating an incident where an application experienced problems between 10:00 and 14:00.

Your investigation requires several thousand Access Log entries. With the GUI workflow, you may have to repeatedly download batches of up to 500 logs.

With the downloader, you can configure the query and time range in the application and retrieve the matching data through the API-based workflow.

The resulting CSV can then be opened in Excel or processed using whatever analysis tools you normally use.

The goal isn’t to replace the F5 XC Console.

The Console remains an excellent place to investigate individual events and interactively explore your environment. The downloader is intended to make bulk collection and offline analysis easier.

Built for a Common Troubleshooting Workflow

One of the main reasons I wanted this to be a GUI application is that troubleshooting doesn’t always happen in an environment where you have time to build a script.

Sometimes the requirement is simply:

“I need all the matching logs for this incident and I need them in CSV.”

If you’re comfortable with APIs, you can build the request yourself. If you’re not, there’s no reason you should have to learn API scripting just to export some logs.

The application tries to bridge that gap.

What You Get

The tool provides a few practical capabilities:

  • Query logs through a GUI
  • Configure the relevant parameters without manually constructing API requests.
  • Specify a time range
  • Focus the query on the period relevant to your investigation.
  • Retrieve large result sets

The application is designed around API-based retrieval rather than the 500-log GUI download workflow.

Export to CSV

Take the resulting data into Excel, Python, Power BI, or another analysis tool.

Windows executable

The project is packaged as a standalone Windows executable, so users don’t need to install Python or configure a development environment.

Why CSV?

CSV is a deliberately simple output format.

Once the logs are downloaded, you’re not locked into another proprietary tool.

You can:

  • Filter and sort them in Excel
  • Build reports
  • Write your own Python analysis
  • Import them into Power BI
  • Share a specific dataset with another team
  • Archive the results for an investigation

The tool focuses on one part of the workflow:

Getting the data out of F5 XC and into a format you can work with.

Screenshots

The application provides a simple workflow for configuring queries, selecting time ranges, monitoring downloads, and exporting results.

View the application screenshots on GitHub

Download

The project is available on GitHub:

F5 XC Log Downloader on GitHub

The latest Windows executable is available from the Releases section.

Download the latest release

No Python installation is required when using the packaged executable.

What’s Next?

This is an ongoing project, and there are several areas where it could be expanded.

I’d also like to hear from other F5 Distributed Cloud community about how they currently collect and analyze logs. And what you think should be added or removed from this tool to improve it further. I’d be keen to try and implement that for the benefit of this vibrant community.

Open Source

The source code is available on GitHub:

View the source code on GitHub

Issues, suggestions, and feature requests are welcome.

A Note on the F5 Distributed Cloud API

The application uses the documented F5 Distributed Cloud Services APIs to retrieve log data.

The APIs provide a powerful way to automate interactions with F5 Distributed Cloud, but using them directly requires a certain level of familiarity with API authentication, requests, queries, and response handling.

This project is intended to make one specific API-driven workflow more accessible through a graphical interface.

Users provide their own authorized F5 XC API credentials, and the application operates within the permissions and access available to those credentials. No API Tokens or credentials ever leave your local machine. Infact it is not even stored in the config file backup which you generate in step 1 of this application. None of the logs downloaded through this app is shared with me or any other person/device.

This is a complete standalone application and only does outbound requests to the F5 XC endpoints for log downloading.

For the official API documentation:

F5 Distributed Cloud API Documentation

Disclaimer

F5 XC Log Downloader is an independent community project and is not an official F5 product, nor is it affiliated with or endorsed by F5.

F5, F5 Distributed Cloud, and related names are trademarks of F5, Inc. They are used in this article solely to identify the platform and APIs with which this tool is designed to work.

Users are responsible for ensuring that they have appropriate authorization to access and export data using the application and for handling exported log data in accordance with their organization’s security and data-handling policies.

All activities carried out during the use of this application is stored locally on your machine. It does not send any data outside your local machine.

Final Thoughts

The motivation behind this project is pretty simple.

The F5 XC Console makes it easy to search and investigate logs, but when you need to download a large number of results, the 500-log download limitation can turn the process into a repetitive exercise.

The APIs provide a more flexible alternative, but working directly with APIs isn’t necessarily something every F5 XC user wants to do.

So I built the middle ground:

A simple GUI for users who want the flexibility of the API without having to write the API code themselves.

If you regularly find yourself downloading F5 XC logs during troubleshooting, security investigations, or support cases, give it a try.

Need to download a ton of F5 XC logs in CSV? Here’s a tool for that.

1 Like