When multiple F5 Networks BIG-IP Local Traffic Manager (LTM) appliances at v10.x send event data to QRadar, the events all display under the same log source.
This issue is due to the Syslog output format of the F5 Networks BIG-IP LTM v10.x appliance, which includes the use of
local/ before the host name in the Syslog header. The F5 Networks BIG-LTM system administrator must either the Syslog template (syslog.tmpl) file or provide a custom Syslog include statement to verify that the format being output does not contain
local/ before the hostname.
Note: QRadar support representatives cannot assist with this change or advise F5 Network BIG-LTM administrators changes. If you are unfamiliar with how to update your F5 Networks BIG-IP LTM appliance, you can contact F5 Networks Support.
Resolving The Problem
A workaround is available to correct the syslog header issue. For the most up to date information please contact F5 Networks support. This issue is referenced on F5 Networks website on the following link:
Where do you find more information?
Was this topic helpful?
16 June 2018