If you want to see real time traffic, you can see it using tcpdump. If you want to see old logs, then you need to have logging server like syslog so F5 will send all the logs to syslog server and then you can analyse same.
I should have been more specific. I know about tcpdump but it'll catch everything hitting that interface which is the public front end on the F5. Is there anyway to filter on the Forwarding VS?
Thinking about it a bit more makes realize I know subnets on each side and can probably make a capture filter to get what I want.