Configuration Guide F5 Big-IP Local Traffic Manager Last Modified: Tuesday, March 11, 2014 Event Source (Device) Product Information Vendor F5 Event Source (Device) Big-IP Local Traffic Manager Supported Versions 9.4, 10.2.0, 11.1, and 11.2.1 Supported Platforms Hardware appliance RSA Product Information Supported Version RSA envision 4.0 and 4.1 Security Analytics 10.0 and later Event Source (Device) Type bigip, 115 Collection Method Syslog Event Source (Device) Class.Subclass Network.Switch Content 2.0 Table Network This document contains the following information for the F5 Big-IP Local Traffic Manager event source: Configuration Instructions Release Notes 20140311-145050 Release Notes 20131031-163922 Release Notes 20130731-180221 Release Notes 20130625-110128 Release Notes 20121130-120146 Release Notes 20121024-162733 Release Notes 20120529-140644 F5 Big-IP Local Traffic Manager Configuration Instructions The envision appliance supports four versions of Big-IP Local Traffic Manager in addition to irule scripting. Use the appropriate set of instructions for your version: Configure Big-IP Local Traffic Manager version 9.4 Configure Big-IP Local Traffic Manager version 10.2.0 Configure Big-IP Local Traffic Manager version 11.1 and 11.2.1 Configure irule support for Big-IP Local Traffic Manager Additionally, you need to configure this event source as a multi-device. For details, see Identify Big-IP Local Traffic Manager as a Multi-Device. Copyright 2012 EMC Corporation. All Rights Reserved.
Configure Big-IP Local Traffic Manager version 9.4 To configure Big-IP Local Traffic Manager version 9.4: 1. Log on to the command line. 2. Change directories to the /etc/syslog-ng/ directory by typing the following command: cd /etc/syslog-ng/ 3. Back up the current syslog-ng.conf file by typing the following command: cp syslog-ng.conf syslog-ng.conf.original 4. Use a text editor to open the syslog-ng.conf file. 5. Add the following to the end of the syslog-ng.conf file: Note: Replace x.x.x.x with the IP address of the RSA envision appliance. # Direct all log information to remote syslog server destination remote_server { udp("x.x.x.x" port (514)); }; filter f_alllogs { level (debug...emerg); }; log { source(local); filter(f_alllogs); destination(remote_server); }; 6. Save the changes to the file. 7. Run the following command to retain your changes to the syslog-ng.conf file after restarting:: bigpipe 8. Restart the syslog-ng utility by typing the following command: bigstart restart syslog-ng 2 Configure Big-IP Local Traffic Manager version 9.4
Configure Big-IP Local Traffic Manager version 10.2.0 To configure Big-IP Local Traffic Manager version 10.2.0: 1. Use an SSH client to access the Big-IP device. 2. Type root, and press ENTER. 3. Enter the Big-IP password. 4. Type bpsh, and press ENTER. 5. Type syslog remote server add host <Platform_IP>, where <Platform_IP> is the IP address of the envision appliance, and press ENTER. 6. Type exit, and press ENTER. 7. Type service syslog-ng stop, and press ENTER. 8. Type service syslog-ng start, and press ENTER. Configure Big-IP Local Traffic Manager version 10.2.0 3
Configure Big-IP Local Traffic Manager version 11.1 and 11.2.1 To configure Big-IP Local Traffic Manager version 11.1 and 11.2.1: 1. Use an SSH client to access the Big-IP device. 2. Type root, and press ENTER. 3. Enter the Big-IP password. 4. Type tmsh, and press ENTER. 5. Type modify /sys syslog remote-servers add { <config_name> { host <Platform_IP> remoteport 514 } } where <config_name> is the name for the syslog event source you are adding and <Platform_IP> is the IP address of your envision appliance. 6. Type list /sys syslog remote-servers and press ENTER. 7. Confirm that your envision appliance has been configured correctly. 8. Type stop sys service all and press ENTER 9. Type start sys service all and press ENTER 10. Type quit, and press ENTER. 4 Configure Big-IP Local Traffic Manager version 11.1 and 11.2.1
Configure irule support for Big-IP Local Traffic Manager EnVision now supports up to eight irule commands. The irule log function must adhere to a name=value format, where each name=value pair is delimited by a double-caret (^^). The following is the general syntax of an irule: log local0. "irule name1=[value1]^^name2=[value2]^^name3=[value3]^^name4=[value4]" Below is a table charting variable names to irule commands that are currently supported by envision: c-ip method uri host s-ip pool-name s-port status Static Variable IP::client_addr HTTP::method HTTP::uri HTTP::host LB::server addr LB::server pool LB::server port HTTP::status irule Command The following is a sample irule that uses all of the supported envision variables: log local0. "irule c-ip=[ip::client_ addr]^^method=[http::method]^^uri=[http::uri]^^host=[http::host]^^sip=[lb::server addr]^^pool-name=[lb::server pool]^^s-port=[lb::server port]^^status=[http::status]" Configure irule support for Big-IP Local Traffic Manager 5
Identify Big-IP Local Traffic Manager as a Multi-Device In order to collect logs for more than one Big-IP device on the same IP address, you must configure the device as a multi-device. To identify Big-IP Local Traffic Manager as a Multi-Device: 1. Click Overview > System Configuration > Services > Devices > Manage Monitored Devices. 2. Under Filtered Devices, click the IP Address used for Big-IP Local Traffic Manager. 3. In the Add/Modify Device window, select Multi device. 4. Click Apply. F5 Big-IP Local Traffic Manager Release Notes (20140311-145050) F5 Big-IP Local Traffic Manager Release Notes (20131031-163922) F5 Big-IP Local Traffic Manager Release Notes (20130731-180221) F5 Big-IP Local Traffic Manager Release Notes (20130625-110128) F5 Big-IP Local Traffic Manager Release Notes (20121130-120146) F5 Big-IP Local Traffic Manager Release Notes (20121024-162733) 6 Identify Big-IP Local Traffic Manager as a Multi-Device
What's New in This Release RSA added support for irules and F5 Big-IP Local Traffic Manager version 11.2.1. F5 Big-IP Local Traffic Manager Release Notes (20120529-140644) What's New in This Release RSA added support for F5 Big-IP Local Traffic Manager version 11.1. Identify Big-IP Local Traffic Manager as a Multi-Device 7