Overview

The F5 integration collects logs from BIG-IP devices, covering:

  • ASM / Advanced WAF — application security violations and bot detections
  • AFM — network firewall and DoS events
  • APM — access policy decisions, SSO, and SAML events
  • LTM — local traffic and pool/member health events
  • System — config changes and admin sessions

Logs are streamed to an Atatus log collector via High Speed Logging (HSL) to a syslog destination, or pulled from the iControl REST API for configuration audit data.


Prerequisites

  • A BIG-IP device running TMOS reachable from your network.
  • Admin credentials, or API user with read-only access.

Step 1: Configure HSL syslog forwarding on BIG-IP

  1. Sign in to the BIG-IP TMUI.
  2. Create a Log Destination that points at your Atatus log collector:
    • Go to System → Logs → Configuration → Log Destinations → Create.
    • Type: Remote High-Speed Log, then create a Pool containing the collector IP and port (typically 514 for syslog).
  3. Create a second Log Destination of type Remote Syslog that references the destination from the previous step. Set the format to Syslog.
  4. Create a Log Publisher that includes that destination.
  5. Attach the publisher to the relevant ASM / AFM / APM logging profiles so events are forwarded.

Step 1b (alternative): Create an iControl REST user

  1. Go to System → Users → User List → Create.
  2. Username: atatus-siem. Role: Auditor (read-only) on All [Read Only].
  3. Save and note the credentials.

Step 2: Connect F5 in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the F5 card and click Connect.
  3. Fill in the form:
Field Description Example
Source syslog for HSL streaming, icontrol for REST API. syslog
Hostname BIG-IP management IP or FQDN (only for icontrol). bigip.example.com
Username iControl REST username. atatus-siem
Password iControl REST password. ••••••••
Verify TLS Whether to validate the device certificate. true
Poll Interval (minutes) How often to pull events (iControl only). 5
Enabled Turn collection on. true
  1. Click Connect.

Note: When using syslog, BIG-IP pushes events directly to your Atatus log collector and the form needs only the Source and Enabled fields.


Verification

  • The F5 card shows Configured.
  • Events appear in Security → Cloud SIEM → Audit Logs → Events with source f5.