Overview
The F5 integration collects logs from BIG-IP devices, covering:
- ASM / Advanced WAF — application security violations and bot detections
- AFM — network firewall and DoS events
- APM — access policy decisions, SSO, and SAML events
- LTM — local traffic and pool/member health events
- System — config changes and admin sessions
Logs are streamed to an Atatus log collector via High Speed Logging (HSL) to a syslog destination, or pulled from the iControl REST API for configuration audit data.
Prerequisites
- A BIG-IP device running TMOS reachable from your network.
- Admin credentials, or API user with read-only access.
Step 1: Configure HSL syslog forwarding on BIG-IP
- Sign in to the BIG-IP TMUI.
- Create a Log Destination that points at your Atatus log collector:
- Go to System → Logs → Configuration → Log Destinations → Create.
- Type: Remote High-Speed Log, then create a Pool containing the collector IP and port (typically
514for syslog).
- Create a second Log Destination of type Remote Syslog that references the destination from the previous step. Set the format to Syslog.
- Create a Log Publisher that includes that destination.
- Attach the publisher to the relevant ASM / AFM / APM logging profiles so events are forwarded.
Step 1b (alternative): Create an iControl REST user
- Go to System → Users → User List → Create.
- Username:
atatus-siem. Role: Auditor (read-only) on All [Read Only]. - Save and note the credentials.
Step 2: Connect F5 in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the F5 card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Source | syslog for HSL streaming, icontrol for REST API. |
syslog |
| Hostname | BIG-IP management IP or FQDN (only for icontrol). |
bigip.example.com |
| Username | iControl REST username. | atatus-siem |
| Password | iControl REST password. | •••••••• |
| Verify TLS | Whether to validate the device certificate. | true |
| Poll Interval (minutes) | How often to pull events (iControl only). | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Note: When using
syslog, BIG-IP pushes events directly to your Atatus log collector and the form needs only the Source and Enabled fields.
Verification
- The F5 card shows Configured.
- Events appear in Security → Cloud SIEM → Audit Logs → Events with source
f5.
+1-415-800-4104