Forum Discussion

Hoang_Hung's avatar
Dec 02, 2020

Sent WAF event from BIG-IQ to Remote server ( SOC arcsight)

Dear all

We had a BIG-IP System running WAF. At this time all event WAF log was sending to BIG-IQ.

So. Do you know solution sent WAF event from BIG-IQ to Remote Sever ( SOC=arcsight)

Note. One time BIG-IP only use a manual Log profile.

 

Thanks all

Hung Hoang

1 Reply

  • Dojs's avatar
    Dojs
    Icon for Cirrostratus rankCirrostratus

    Hi,

    you can send to both together.

     

    TIP:

    1. Create a Pool with your IP of ArcSight
    2. Create Log Destination HighSpeed with the pool
    3. Create Log Destination Remote Syslog with the HSL above
    4. Inside of remote-logging-publisher of WAF, insert destination create above

     

    See if works, for me works in QRadar