Security Compliance

Integrate F5 Big-IP with SolarWinds SEM

This article provides steps on configuring F5 log settings to send syslogs to SEM and configuring the F5 connectors in the SEM console.

First published date

10/31/2018 3:50 PM

Last published date

10/31/2018 3:50 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager) and describes how to configure and forward F5 Big IP Syslogs messages to SEM and configure the F5 connectors in the SEM console so that SEM can parse and normalize these messages.

Product section

Security Event Manager

Resolution

  1. This is a prerequisite before you go to Step 2 below. Configure the F5 appliance (© 2017 F5 Networks, Inc., available at https://support.f5.com/, obtained on June 20, 2017) to send syslogs to the SEM server on port 514. If you are not sure, please contact F5 support.
  2. Configure one or more of the below F5 Big-IP connectors from SEM web console > Configure > Manager based on your need to monitor the type of logs in SEM. For sample steps on how to add manager connector refer to Add a syslog device to SEM (solarwinds.com). When configuring connector file path, use an empty Syslog facility where possible and don't mix it with other logs from other syslog devices like cisco or juniper etc.
F5 Connector Name Connector Purpose / Type of log messages
F5 BigIP BSD daemon messagesCollects events about services running on the F5 appliances.
F5 BigIP HTTPD specificCollects web traffic events (primarily HTTP errors and warnings) from F5 appliances.
F5 BigIP messagesCollects authentication and service-related events on the F5 appliances.
F5 General BIG-IP specific messagesCollects events specific to LTM (local traffic manager) and ASM (Application Security Manager) on the F5 appliances.
  1. Start the connectors that you enabled. 
  2. Once SEM appliance receives any messages to any of the connectors configured above, it will display New nodes and then adds them automatically to the Nodes list in SEM web console >  configure > Nodes

If for some reason the F5 Big IP's IP's detected or add, then please refer to Troubleshoot network and syslog device logging in SEM 
If you identified the F5 logs are sent to SEM and you can see in your Firewall application traffic going from F5 to SEM appliance, then it's time to open ticket with Solarwinds Tech support