Configuring BIG-IP

Configuring a Repo for BIG-IP

  1. Go to Settings >> Configuration from the navigation bar and click Repos.

  2. Click Add.

  3. Enter a Repo Name. It cannot contain spaces or special characters.

  4. Select a Repo Path and set a Retention Day. You can add or remove multiple Repo Path and Retention Day.

  5. Select a Remote LogPoint

  6. Set a Available for (day). To reset, click Remove.

  7. Click Submit.

_images/addrepo.png

Adding a Repo

Adding a Normalization Policy for BIG-IP

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select the Compiled Normalizer and Normalization Packages for BIG-IP.

  5. Click Submit.

_images/N1.png

Adding a Normalization Policy

Configuring a Processing Policy for BIG-IP

  1. Go to Settings >> Configuration from the navigation bar and click Processing Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select the previously created Normalization Policy.

  5. Select the Enrichment Policy and Routing Policy.

  6. Click Submit.

_images/pp.png

Adding a Processing Policy

Adding BIG-IP as a Device in Logpoint

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click Add.

  3. Enter a device Name.

  4. Enter the BIG-IP server IP address(es).

  5. Select the Device Groups.

  6. Select an appropriate Log Collection Policy for the logs.

  7. Select a collector or a forwarder from the Distributed Collector drop-down.

Note

It is optional to select the Device Groups, the Log Collection Policy and the Distributed Collector.

  1. Select a Time Zone. The timezone of the device must be same as its log source.

  2. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

  3. Click Submit.

Create Device Panel

Adding BIG-IP as a Device

Configuring the Syslog Collector for BIG-IP

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click the Add icon from Actions of the previously added device.

  3. Click Syslog Collector.

  4. Select Syslog Parser as Parser.

  5. Select the previously created Processing Policy.

  6. Select the Charset.

  7. In Proxy Server, select None

  8. Click Submit.

Available Collectors Fetchers Panel

Configuring Syslog Collector


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support