Forum Discussion

brandon_liew_ch's avatar
brandon_liew_ch
Icon for Nimbostratus rankNimbostratus
Sep 11, 2013

[Reporting - Chart for monthly]

Dear All,

 

Currently, we just deploy a F5 ASM Firewall into our network. It's running on BIG-IP 11.2.1 Build 862.0 Hotfix HF2. The F5 ASM also integrates with Splunk. All the illegal request will log to Splunk. I'm having some issues generating a monthly report (Top attacker for blockeed request) using the built in feature provided by F5. When I'm trying to generate a report for a month i will only show 2 weeks. Is there a configuration i require to change for me to get a monthly report? FYI, i prefer report generating from F5 rather than Splunk

 

Thanks

 

4 Replies

  • you mean with a report that you use Charts? and you have set it to Time Period: Month? could be the F5 has already cycled the information, when you search on events how far back can you go?

     

  • Yes, u r right. Only cycle for a month. Example, Let say from 11 August 2013 - 11 September 2013 The maximum data i am able to get is only 1 week plus to 2 weeks

     

  • if you extend the period you will probably see there simply is no data for the first part of the period. the ASM only keeps the data upto a certain point and then deletes it to keep enough space available.

     

    I understand you want to use the ASM for this but ASM is not meant as a reporting device. personally i would expect you could get much better data with Splunk, but im not that familiar with it.

     

  • Agree with you. But I'm trying to integrate with Splunk but having problem grabbing the logs.