Configuring DSMs
F5 Networks BIG-IP ASM
103
F5 Networks BIG-IP
ASM
The SIEM F5 Networks BIG-IP Application Security Manager (ASM) DSM collects
web application security events from a BIG-IP ASM device using syslog. Before
receiving events in SIEM, you must configure your F5 Networks ASM device with a
logging profile to forward application events to SIEM.
To configure a logging profile:
Step 1
Log in to the F5 Networks BIG-IP ASM device user interface.
Step 2
In the navigation pane, select
Application Security > Options
.
Step 3
Click
Logging Profiles
.
The Logging Profiles is displayed.
Step 4
Click
Create
.
The Create New Logging Profile is displayed.
Step 5
From the
Configuration
drop-down list box, select
Advanced
.
Advanced configuration options are displayed.
Step 6
Configure the following parameters:
a
Type a Profile Name.
For example:
SIEM
.
b
Optional. Type a Profile Description.
NOTE
If you do not want data logged locally as well as remotely, you must clear the
Local Storage check box.
c
Select the
Remote Storage
check box.
d
From the
Type
drop-down list box, select
Reporting Server
.
e
From the
Protocol
drop-down list box, select
TCP
.
f
Configure the
Server Addresses
fields:
-
IP address
- Type the IP address of the SIEM Console.
-
Port
- Type a port value of 514.
g
Select the
Guarantee Logging
check box.
NOTE
Enabling the Guarantee Logging option ensures the system log requests continue
for the web application when the logging utility is competing for system resources.
Enabling the Guarantee Logging option may slow access to the associated web
application.
h
Select the
Report Detected Anomalies
check box, to allow the system to log
details.
i
Click
Create
.
The display refreshes with the new logging profile.
Summary of Contents for Security Information and Event Manager
Page 2: ......
Page 8: ......
Page 20: ......
Page 22: ......
Page 24: ......
Page 26: ......
Page 32: ......
Page 34: ......
Page 36: ......
Page 38: ......
Page 44: ......
Page 58: ......
Page 90: ......
Page 92: ......
Page 94: ......
Page 114: ......
Page 116: ......
Page 122: ......
Page 124: ......
Page 126: ...Configuring DSMs 110 FIREEYE...
Page 128: ......
Page 130: ......
Page 132: ......
Page 136: ......
Page 140: ......
Page 144: ......
Page 172: ......
Page 176: ...Configuring DSMs 160 ISC BIND...
Page 180: ......
Page 182: ......
Page 184: ......
Page 204: ......
Page 224: ......
Page 246: ......
Page 250: ......
Page 256: ......
Page 260: ......
Page 276: ......
Page 282: ......
Page 284: ......
Page 306: ......
Page 308: ......
Page 318: ......
Page 322: ......
Page 324: ......
Page 346: ......
Page 356: ......
Page 366: ......
Page 384: ......
Page 392: ......
Page 394: ......
Page 396: ......
Page 398: ......
Page 404: ......
Page 426: ......