The log profile you created must be associated with a virtual server in the
Security Policy tab. This association allows the virtual server to process
your network firewall events, along with local traffic.
About this task
Take the following steps to associate the profile to a virtual server.
Procedure
-
From the navigation menu, select .
-
Click the name of a virtual server to modify.
-
From the Security tab, select Policies.
-
From the Log Profile list, select Enabled.
-
From the Profile field, in the Available list,
select Logging_Profile or the name you specified in Creating a logging profile
and click <<.
This clicking action moves the Logging_Profile option from the Available
list to the Selected list.
-
Click Update to save your changes.
The configuration is complete. The log source is added to IBM
QRadar as F5 Networks BIG-IP AFM
syslog events are automatically discovered. Events that are forwarded to QRadar by F5 Networks BIG-IP AFM
are displayed on the Log Activity tab of QRadar.