Updated Date: 07/07/2026
Creating a Fraud Protection logging profile
Before creating a Fraud Protection logging profile, you need to configure a log publisher that will send the Fraud Protection logs to the third-party platform of your choice. Your log publisher must have a log destination of one of the following types: Remote High-Speed Log, Local Syslog, Remote Syslog, or Splunk.
Create a Fraud Protection logging profile so that you can receive a log of information on client attempts to login to the website protected by your anti-fraud profile and information on FPS alerts sent by the BIG-IP system.
-
On the Main tab, click Security > Event Logs > Logging Profiles.
The Logging Profiles list screen opens.
-
Click Create.
The Create New Logging Profile screen opens.
-
In the Profile Name field, type a unique name for the profile.
-
Select the Enabled check box by Fraud Protection.
The screen displays the Fraud Protection tab.
-
On the Fraud Protection tab, for Configuration, select Advanced.
Note: Advanced configuration is optional. However, if you choose Basic configuration, you cannot set a rate-limit for sending log messages and the rate-limit is unlimited. Also, with Basic configuration you cannot select data items to be URL-encoded in log messages.
-
For Publisher, select your log publisher from the list.
-
For Rate-Limit Template, choose either Default or User-Defined.
The Rate-Limit Template settings define the notification that appears when the rate-limit for sending logs is exceeded.
If you choose User-Defined, define the Rate-Limit template as follows:
-
In the Available Items list, select the data items you want to appear in rate-limit exceeded notifications and move them to the Selected Items list.
-
For Select Format, choose one of the following:
-
Field-List: Specifies that the notification displays only the items you move from the Available Items list to the Selected Items list. The delimiter that you choose separates the items in the notification. After choosing a delimiter, click Format to see the revised template.
-
Key-Value Pairs: Specifies that the notification displays the actual name of the selected item as being equal to the value of that item. For example, if you choose Key-Value Pairs format and one of your selected items is timestamp, if the value of timestamp is 1549888174, in the log message you will see
timestamp=1549888174.After choosing a delimiter, click Format to see the revised template.
-
-
-
If you want data items to be URL-encoded in log messages and in the rate-limit exceeded notification, at Fields to Encode select Only and then select the data items from the Available Items list and move them to the Selected Items list.
-
For Login Attempt, select the Enabled check box.
The Template and Rate Limit settings for Login Attempt messages appear.
-
For the Login Attempt Template, choose either Default or User-Defined.
If you choose User-Defined, define the Login Attempt template as follows:
-
In the Available Items list, select the data items you want to appear in login attempt messages and move them to the Selected Items list.
-
For Select Format, choose one of the following:
-
Field-List: Specifies that the message displays only the items you move from the Available Items list to the Selected Items list. The delimiter that you choose separates the items in the message. After choosing a delimiter, click Format to see the revised template.
-
Key-Value Pairs: Specifies that the message displays the actual name of the selected item as being equal to the value of that item. For example, if you choose Key-Value Pairs format and one of your selected items is timestamp, if the value of timestamp is 1549888174, in the log message you will see timestamp=1549888174.
After choosing a delimiter, click Format to see the revised template.
-
-
-
For Login Attempt Rate Limit, select either Unlimited or Specify.
If you choose Specify, type your preferred rate limit in the text box.
Note: Rate Limits are calculated per-second, per TMM, with each TMM throttling as needed, independently of other TMMs.
-
For Alert, select the Enabled check box.
The Template and Rate Limit settings for Alert messages appear.
-
For the Alert Template, choose either Default or User-Defined.
If you choose User-Defined, define the Alert template as follows:
-
In the Available Items list, select the data items you want to appear in alert messages and move them to the Selected Items list.
-
For Select Format, choose one of the following:
-
Field-List: Specifies that the message displays only the items you move from the Available Items list to the Selected Items list. The delimiter that you choose separates the items in the message. After choosing a delimiter, click Format to see the revised template.
-
Key-Value Pairs: Specifies that the message displays the actual name of the selected item as being equal to the value of that item. For example, if you choose Key-Value Pairs format and one of your selected items is timestamp, if the value of timestamp is 1549888174, in the log message you will see
timestamp=1549888174.After choosing a delimiter, click Format to see the revised template.
-
-
-
For Alert Rate Limit, select either Unlimited or Specify.
If you choose Specify, type your preferred rate limit in the text box.
Note: Rate Limits are calculated per-second, per TMM, with each TMM throttling as needed, independently of other TMMs.
-
Click Create.
The BIG-IP system saves your logging profile and the list of logging profiles appears.
After you have created a Fraud Protection logging profile, you need to associate the logging profile with an anti-fraud profile.