Configuring F5 Networks BIG-IP ASM
The JSA F5 Networks BIG-IP Application Security Manager (ASM) DSM collects web application security events from BIG-IP ASM appliances by using syslog.
To forward syslog events from an F5 Networks BIG-IP ASM appliance to JSA, you must configure a logging profile.
A logging profile can be used to configure remote storage for syslog events, which can be forwarded directly to JSA.
- Log in to the F5 Networks BIG-IP ASM appliance user interface.
- On the navigation pane, select Application Security >Options.
- Click Logging Profiles.
- Click Create.
- From the Configuration list, select Advanced.
- Type a descriptive name for the Profile Name property.
- Type a Profile Description.
If you do not want data logged both locally and remotely, clear the Local Storage check box.
- Select the Remote Storage check box.
- From the Type list, select one of the following
options:
In BIG-IP ASM V12.1.2 or earlier, select Reporting Server.
In BIG-IP ASM V13.0.0 or later, select key-value pairs.
- From the Protocol list, select TCP.
- For the IP Address field, type the IP address of the JSA console and for the Port field, type a port value of 514.
- Select the Guarantee Logging check box.
Note Enabling the Guarantee Logging option ensures the system log requests continue for the web application when the logging utility is competing for system resources. Enabling the Guarantee Logging option can slow access to the associated web application.
- Select the Report Detected Anomalies check box to allow the system to log details.
- Click Create.
The display refreshes with the new logging profile. The log source is added to JSA as F5 Networks BIG-IP ASM events are automatically discovered. Events that are forwarded by F5 Networks BIG-IP ASM are displayed on the Log Activity tab of JSA.
Syslog Log Source Parameters for F5 Networks BIG-IP ASM
If JSA does not automatically detect the log source, add a F5 Networks BIG-IP ASM log source on the JSA Console by using the syslog protocol.
When using the syslog protocol, there are specific parameters that you must use.
The following table describes the parameters that require specific values to collect syslog events from F5 Networks BIG-IP ASM:
Table 1: Syslog Log Source Parameters for the F5 Networks BIG-IP ASM DSM
Parameter | Value |
---|---|
Log Source type | F5 Networks BIG-IP ASM |
Protocol Configuration | Syslog |
Log Source Identifier | Type the IP address or host name for the log source as an identifier for events from your F5 Networks BIG-IP ASM devices. |