22-Jan-2020 21:41
Hi guys
I`m searching method which can logging or inspecting traffic information.
Target license are LTM and CGNAT.
I have looking for Telemetry streaming but that seems providing sampling information.
I need full traffic information not sampling data. also don`t need mirroring.
I think using i-Rule with HSL can be a method but I`m wondering how much traffic can be logging.
-> how much means about CPS 150K.
-> and BIGIP`s disk can be able to hold the logs.
Solved! Go to Solution.
22-Jan-2020 23:05
Hi,
Yes, the purpose of HSL is for syslog protocol. You can forward to external syslog server by TCP / UDP based on syslog receiver.
22-Jan-2020 22:48
Hi,
F5 not suggest to store log locally. From my experience F5 support recommend customer forward log to SIEM / Big Data Solution / BIG-IQ instead.
22-Jan-2020 22:50
Hi.
Then is there possible method not store logs in box but forward to remote?
22-Jan-2020 22:54
Hi,
Previously message might not clear for you. If we talk about technical perspective.
22-Jan-2020 23:03
Hi.
I don`t have security module.
So select 2.
there are 2 selections.
before select, I`m first time out HSL.
Does HSL can send syslog remote not store on BIGIP?
22-Jan-2020 23:05
Hi,
Yes, the purpose of HSL is for syslog protocol. You can forward to external syslog server by TCP / UDP based on syslog receiver.
22-Jan-2020 23:08
Hi.
Thanks for your advice.