F5 LTM (v1.0.18)

You can use this pack to automate traffic management use cases in integration with F5 Local Traffic Manager (LTM), the integration with F5 LTM included with the pack comes with several commands to get LTM information about nodes, pools and pool members, along with that some of those commands can be used to automate remediation actions such as disabling an active node.

Author
Ayman Mahmoud
Support
community
Categories
Network Security

Integrations (1)

Modeling rules (1)

Parsing rules (1)

README

F5 BIG-IP LTM

This pack includes Cortex XSIAM content.

Configuration on Server Side

You need to configure F5 LTM to forward logs in Syslog format.

Go to F5 LTM and navigate to System -> Logs -> Configuration -> Remote Logging and enter the following:

  1. Remote IP: add the Broker VM IP address.
  2. Remote Port: add the designated Broker VM port.

Press Add and Update to apply the new configuration.

Server Screenshot

Collect Events from Vendor

In order to use the collector, use the Broker VM option.

Broker VM

To create or configure the Broker VM, use the information described here.

You can configure the specific vendor and product for this instance.

  1. Navigate to Settings > Configuration > Data Broker > Broker VMs.
  2. Right-click, and select Syslog Collector > Configure.
  3. When configuring the Syslog Collector, set the following values:
    • vendor as vendor - f5
    • product as product - ltm

What does this pack do?

For more information, visit the Cortex XSOAR and XSIAM Developer Docs.