remote log
3 TopicsF5 ASM remote logging format (Splunk KV pairs)
Hi, I had referred to F5 resource for the details about the fields found in the ASM logs (f5 AWAF). However, it seem like it doesn't have the full details of every fields found in the logs. Do we have a full documentation for the fields in the logs? The purpose to understand the log format, and what each fields would be referred in different scenario. (I don't have access to F5 web portal, therefore unable to compare the fields in f5. ) The sample log line: <134>Aug 17 11:18:15 <host> ASM:unit_hostname="<host_fqdn>",management_ip_address="x.x.x.x",management_ip_address_2="N/A",http_class_name="/Common/app_policy",web_application_name="/Common/app_policy",policy_name="/Common/sample_policy",policy_apply_date="2026-01-31 10:23:08",violations="N/A",support_id="18000000000000000000",request_status="passed",response_code="200",ip_client="y.y.y.y",route_domain="0",method="GET",protocol="HTTPS",query_string="N/A",x_forwarded_for_header_value="y.y.y.y",sig_ids="N/A",sig_names="N/A",date_time="2026-08-17 11:18:14",severity="Informational",attack_type="N/A",geo_location="N/A",ip_address_intelligence="N/A",username="N/A",session_id="xxxxxxxxxxxxxxxx",src_port="12345",dest_port="443",dest_ip="z.z.z.z",sub_violations="N/A",virus_name="N/A",violation_rating="0",websocket_direction="N/A",websocket_message_type="N/A",device_id="N/A",staged_sig_ids="N/A",staged_sig_names="N/A",threat_campaign_names="N/A",staged_threat_campaign_names="N/A",blocking_exception_reason="N/A",captcha_result="not_received",microservice="N/A",tap_event_id="N/A",tap_vid="N/A",vs_name="/Common/app_https_vs",sig_cves="N/A",staged_sig_cves="N/A",uri="/login.php",fragment="N/A",request="GET /login.php HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36\r\nHost: abc.com\r\nAccept: */*\r\nCookie: xxxxxxxxxx=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx; xxxxxxxxxx=xxxxxxxxxxxxxxxxxxx\r\nX-Forwarded-For: y.y.y.y\r\n\r\n",response="Logging rate limit reached" Based on my understanding, (am I correct?) "date_time" would be the exact event timestamp when WAF received the event "violation_rating" is rating between 1 and 5 that ranks the severity of any violations associated with the request. 1 is most likely a false positive and 5 is most likely an attack. However, I don't have enough info about the other fields: route_domain Is the "syslog_priority" actually calculated based on the "severity"? E.g., if the facility is local0 (16), then <134> would represent "Informational". sig_ids, sig_names, staged_sig_ids, staged_sig_names, sig_cves, staged_sig_cves. Are these IDs and names defined by WAF's own signatures? I mostly see "N/A" for these fields. Are they related to "violations" or "sub_violations"? ip_address_intelligence websocket_direction, websocket_message_type. Are these fields mostly related to protocol like WSS? threat_campaign_names, staged_threat_campaign_names blocking_exception_reason microservice tap_event_id, tap_vid fragment Wanna ensure that I can be familiar with these fields so that it would help us in log analysis. Thanks in advance.78Views0likes3CommentsCEF logs F5
Hello, Is it possible to configure F5 appliances (LTM and Big IP DNS) to send logs in CEF format to a remote syslog server? I've configured remote logging, but I haven't found a way to format the logs. BIG-IP 15.1.2.1 Build 0.0.10 Point Release 1 Thanks in advanceSolved699Views0likes7CommentsF5 ASM - Stagged blocking settings is not send to remote log
Hi All, refer to support article https://support.f5.com/csp/article/K15215363 that said stagged attack signature will not send to remote log, but i have some another stagged policy settings is file type, which while i was export from the remote log the url value are blank, but the actual event in f5 are there. my assumption the stagged event log not send to remote log. is that also will not send to remote log? *that attack signature is enforced622Views0likes1Comment