Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

This quick start guide will help Accenture MDR customers configure F5® BIG-IP Access Policy Manager® (APM) to send logs to the Log Collection Platform (LCP). 

The document includes the following topics:

Supported Versions

A list of supported versions is available in the Accenture MDR Supported Products List document (Accenture_MSS_Supported_Products_List.xlsx) which can be found in Accenture MDR Portal.

Port Requirements

Table 1-1: Port requirements for LCP communication.

Source

Destination

Port

Description

F5 BIG-IP APM

LCP

514 (UDP)

Default port

Configuring F5 BIG-IP APM

To configure the F5 BIG-IP APM to send syslog events, follow the steps below.

  1. Login the BIG-IP Configuration Utility portal with Administrator privileges.

  2. Go to Main > System > Logs > Configuration > Remote Logging.

  3. In the Properties section, provide the following details:

  • Remote IP - LCP_IP_Address

  • Remote Port - 514

4. Click Add.

5. Click Update to add the configuration.

Note: 

  • For logs coming from APM, only the BSD syslog format is supported.

  • For LTM along with APM deployment, remote syslog configuration is not required. Based on the signatures in the APM, the collector processes only APM logs.

  • The F5 BIG-IP APM event collector supports multi-threading logs from LTM 11.6 device.

  • Please use below format of iRule if you are using iRule. This is the only format of iRule which we are supporting.

name log_header_requests
height 150

 LCP Configuration Parameters

Table 1-2: The F5 Big IP(APM) event collector (Syslog -3781) properties to be configured by MSS are shown in the table.

Property

Default Value

Description

Protocol

UDP

The default protocol for syslog. F5 BIG-IP APM does not support TCP.

IP Address

F5 BIG-IP APM interface IP address

Logging device IP address mentioned in the Pre-Installation Questionnaire (PIQ).

Note: If the device sends logs using multiple interfaces, contact the Accenture MDR onboarding team.

Signatures

apd[,apmd[,tmm[,tmm1[,tmm2[,tmm3[,tmm4[,tmm5[,

tmm6[,tmm7[,tmm8[,websso.0[,websso.1[,websso.2[,

websso.3[, websso.4[,websso.5[,websso.6[,

websso.7[,websso.8[, dnscached[

MSS recommended signatures processed by the F5 BIG-IP APM event collector.

Port Number

514

The default port number for syslog.

Note: The LCP can be configured to listen on a non-standard port, please advise the Accenture MDR onboarding team if this is a requirement.

 

  • No labels