F5 ASM
Overview
F5 ASM is a web application firewall designed to protect web applications from common and advanced attacks, ensuring secure and reliable application traffic.
This pack includes
- Remote logging manual.
- Modeling Rules for Application Security Manager logs.
Broker VM
You will need to use the information described here.\
You can configure the specific vendor and product for this instance.
- Navigate to Settings -> Configuration -> Data Broker -> Broker VMs.
- Right-click, and select Syslog Collector -> Configure.
- When configuring the Syslog Collector, set:
- vendor as F5
- product as ASM
Setting up remote logging
- On the Main tab, click SecurityEventLogs -> Logging -> Profiles.
The Logging Profiles list screen opens. - Click Create.
The Create New Logging Profile screen opens. - In the Profile Name field, type a unique name for the profile.
- Select the Application Security check box.
The screen displays additional fields. - On the Application Security tab, for Configuration, select Advanced.
- From the Storage Destination list, select Remote Storage.
Additional fields related to remote logging are displayed. - From the Logging Format list, select Common Event Format (ArcSight)
- For the Protocol setting, select the protocol that the remote storage server uses: TCP (the default setting), TCP-RFC3195, or UDP.
- For Server Addresses, Type theIP Address of the Broker VM and Port (default is 514), and click Add.
- Click Finished.
For more information about remote logging, refer to this documentation.
