F5 Networks BIG-IP AFM

The F5 Networks BIG-IP Advanced Firewall Manager (AFM) DSM for IBM® QRadar® accepts syslog events that are forwarded from F5 Networks BIG-IP AFM systems in name-value pair format.

About this task

QRadar can collect the following events from F5 BIG-IP appliances with Advanced Firewall Managers:

  • Network events
  • Network Denial of Service (DoS) events
  • Protocol security events
  • DNS events
  • DNS Denial of Service (DoS) events

Before you can configure the Advanced Firewall Manager, you must verify that your BIG-IP appliance is licensed and provisioned to include Advanced Firewall Manager.


  1. Log in to your BIG-IP appliance Management Interface.
  2. From the navigation menu, select System > License.
  3. In the License Status column, verify that the Advanced Firewall Manager is licensed and enabled.
  4. To enable the Advanced Firewall Manager, select System > Resource > Provisioning.
  5. From the Provisioning column, select the check box and select Nominal from the list.
  6. Click Submit to save your changes.