Manual Chapter : Access Reporting and Statistics

Applies To:

  • BIG-IQ Centralized Management

    7.1.0

Access Reporting and Statistics

Access reports focus on session and logging data from Access devices (managed devices with APM licensed and provisioned). F5 Secure Web Gateway Services reports focus on user requests (for URLs or applications, for example) from Access devices with Secure Web Gateway Services provisioned. BIG-IQ Centralized Management Access also supports high availability. Thus, users can view both Access and SWG reports on a secondary BIG-IQ system.

Access reports and SWG reports provide the following features.

  • Reports on any combination of discovered devices, Access groups, and clusters

  • Graphs for typical areas of concern and interest, such as cross-geographical comparisons or top 10 issues

  • Tabular data to support the graphs

  • Granular user data

  • Ability in some screens to drill down from summarized data to details

  • Ability to save data to CSV files

Before you can produce Access reports and SWG reports, you must ensure that these tasks are already complete:

  • A BIG-IQ data collection device is configured in the BIG-IQ system.
  • Add the BIG-IP devices to the BIG-IQ inventory.
  • Discover the BIG-IP devices with the Access service configuration.
  • Run the data collection device configuration setup on the devices from the Access Reporting screen.

The All Devices option for Access reports includes data from the devices that are currently managed (discovered) in the BIG-IQ system. This is in addition to data from devices that were managed at some point during the report timeframe, but that are not currently managed. With All Devices selected, if data from unmanaged devices exists, it displays in reports.

An unmanaged device might be unmanaged temporarily or permanently. Any time a configuration management change causes APM® to be undiscovered, the device and its data are moved to All Devices until APM is re-discovered on the device.

You cannot generate a report for an unmanaged device. However, you can generate a report for the timeframe when the device was managed, and then search the report for the unmanaged device name. In the Summary report, All Active Sessions includes the number of sessions that were active on the device when it became unmanaged. Those sessions stay in the Summary and in the Active sessions reports until the next session status update, which occurs every 15 minutes.

For Access Policy Manager (APM) to have monitoring data for your device, you must add the BIG-IP device to the BIG-IQ Centralized Management system. The system must then discover the device, and a user must run the Access remote logging configuration on the device. You can use the Access Summary dashboard to view aggregated data from APM policies managed by this BIG-IQ environment. Data you can view includes authentication, connectivity, user, session, and license information. To do so, on the Main tab, navigate to Monitoring > DASHBOARDS > Access > Access Summary.

Widget Title

Description

ACCESS GROUP/DEVICE

Select Managed Devices or select one or more of these options:

  • Select All Devices to view data from all BIG-IP devices managed by this BIG-IQ.
  • Select All Managed Devices to view data from all devices provisioned with APM managed by this BIG-IQ.
  • Select the name of an Access group name to include all devices in a specified Access group.
  • Select the name of a cluster to view the reported Access data from a cluster of BIG-IP devices.
  • Select the name of a BIG-IP device to view APM data from the device in this report.

TIMEFRAME

Adjust the time frame to reflect the period for which you would like to view data. You can do this by either: selecting the interval from the TIMEFRAME drop down menu, or by dragging the date selector from the horizontal widget below it.

Note: You can also select a timeframe between two specific dates or before or after a selected date by selecting Between,Before, or After and then selecting a date or date range from the calendar widget.

Once you have selected the time frame or date range you are interested in, the data on this dashboard will change to reflect the new time period.

All Active Users

From this dashlet, you can view all unique users with an active session using this device or devices. You can drill down on this information and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.

Sessions Created

From this widget, you can view all new sessions initiated during the timeframe currently displayed at the top of the page. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.

Unique Users

View the number of unique users during the timeframe specified at the top of the page. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.

Sign-In Denied

From this widget, you can view the number of sessions that have been denied. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.

Active Sessions Over Time

You can track the Average Established number of sessions in an interval of time, the Average Attempted number of sessions in one interval of time, the Maximum Established number of sessions in an interval of time, and the Maximum Attempted number of sessions in an interval of time. You can remove any of these components from the graph to focus your report by selecting the name of the component in the ledger at the top right corner of the chart.

The time intervals with the horizontal axis will adjust depending on the length of time you select in the Timeframe widget at the top of the page. For example, longer time frames will yield larger intervals for data collection and shorter time frames will yield shorter intervals for data collection. Average and Maximum refer to the aggregated data in a single unit of time on the horizontal axis. You can check what units of time the graph is using in the top left corner of the chart.

Denied Sessions / Auth Failures Over Time

This widget allows you to track denied sessions and Authentication failures against each other. You can remove either denies sessions or Authentication failures from the data set by selecting either of these components in the legend at the top right corner of the chart.

Top 3 Devices by License Usage

You can view devices by license usage in one of three categories: Access Sessions, Connectivity Sessions, and Secure Web Gateway (SWG) Sessions. Click on any of these categories to view the license usage for each, including the threshold and usage limit of each of the top three devices. By hovering over the bar graph for a device, you can view how many users are licensed for this device (displayed as the Limit) and how many are currently using it (displayed as Usage.

Session Count Distribution Across Countries

Use this widget to select a geographic location to view from the map to view more information about session logon locations in another dashboard. You can also view more data about sessions originating from unknown location by clicking on Unknown Locations at the bottom of the dashlet. To zoom in or out on the map widget, use the + and - icons.

Top Users by Session Count

You can view the top 10 users with the most sessions for this device or set of devices. To learn more about the activity of each user, select the name to navigate to a summary dashboard displaying usage data for this user only.

When you upgrade a BIG-IQ® Centralized Management system without taking a snapshot, it deletes all reporting data, including both Access and SWG reports. After upgrading, users cannot obtain these reports from the BIG-IP® devices. To prevent the loss of reports, users should take an Elasticsearch snapshot before upgrading, and restore the snapshot after upgrading. For more information on elastic snapshots, refer to F5 BIG-IQ Centralized Management: Upgrading Logging Nodes to Version x.x.

Problem
A session is over, but it continues to display in the Active sessions report.
Resolution
If a session starts when logging nodes are up and working, but terminates during a period when logging modes are unavailable, the session remains in the Active sessions report for 15 minutes. After 15 minutes, the session status is updated and the session is dropped from the report.
Problem
Active sessions are included in the Summary and Active sessions reports for a device that is no longer managed.
Resolution
Sessions were active on a device when it was removed from an Access group and became unmanaged. Sessions that were active when the device became unmanaged remain counted in All Active Sessions on the Summary screen and stay in the Active sessions report until the next session status update, which occurs every 15 minutes.
Problem
A session is over, but Session Termination and Session Duration are blank in a session report.
Resolution
If a session starts when logging nodes are up and working but terminates during a period when logging nodes are unavailable, the session termination is not recorded and the session duration cannot be calculated.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use the TIMEFRAME list at the top of any Access or SWG report to change the report time period.

  1. At the top of the screen, click Monitoring.

  2. To set a predefined timeframe, select one of these from the TIMEFRAME list: Last hour, Last day, Last week, Last 30 days, Last 3 months.

  3. To set a custom timeframe, select one of these from theTIMEFRAME list:

    • Between: Click each of the additional fields that display to select dates and times. The report displays the records between those dates and times.
    • Before: Click the additional fields that display to select a date and a time. The report displays the records before that date and time.
    • After: Click the additional fields that display to select a date and a time. The report displays the records after that date and time.

When you upgrade a BIG-IQ® Centralized Management system without taking a snapshot, it deletes all reporting data, including both Access and SWG reports. After upgrading, users cannot obtain these reports from the BIG-IP® devices. To prevent the loss of reports, users should take an Elasticsearch snapshot before upgrading, and restore the snapshot after upgrading. For more information on elastic snapshots, refer to F5 BIG-IQ Centralized Management: Upgrading Logging Nodes to Version x.x.

When you run an Access report or an SWG report, Access can get up to 10,000 records to display to you. After you scroll to the end of those 10,000 records, Access displays a message. At that point, all you can do is select fewer devices or select a shorter timeframe.

BIG-IQ Access users can configure managed BIG-IP devices in an Access Group to act as an OAuth authorization server or a resource server. Once you have configured an OAuth Authorization Server, you can use BIG-IQ to monitor the number of the tokens requested and generated by the OAuth Authorization Server, view the number of client applications used to access external resources, and view the number of errors the OAuth Authorization Server has encountered. You can also organize the Authorization Server Summary report by grant type or view data from a specific time period.

Use the Authorization Server Summary dashboard to troubleshoot issues with the BIG-IP device you have configured as an OAuth Authorization Server.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

You can use BIG-IQ Centralized Management to generate a summary report for your OAuth authorization server. Controls on this screen work together so you can fine-tune the statistics display. You may also use this workflow to revoke an OAuth token.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > OAuth > Authorization Server > Authorization Server Summary.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To change the OAuth authorization server you view in this report, make a selection from the AUTHORIZATION SERVER list.

  5. To change the OAuth grant type displayed on this screen, make a selection from the GRANT TYPE dropdown list. You can choose to generate a report for Resource Owner Password Credentials (ROPC) grant types, implicit grant types, or authorization code grant types.

  6. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  7. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  8. To learn more details for the categories across the top of the page, select Total Access Tokens, Token Errors, Unique Users, Unique Client Apps, or Introspection Errors. BIG-IQ displays a screen with additional metrics for this recorded category.

    Note: For example, to view all token errors tha result from the authorization code request type, select Token Errors, then view the data you are interested in under the chart titled TOP ERRORS BY REQUEST TYPE.

  9. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  10. To add or remove metrics for token generation, on the TOKEN GENERATION REQUESTS OVER TIME chart, click on the name of the metric that you want to remove..

  11. You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 USERS, TOP 10 CLIENT APPS, TOP 10 RESOURCE SERVERS, TOP 10 OAUTH CLIENT IP’S, GEOLOCATION DISTRIBUTION, and USER PLATFORM DISTRIBUTION.

    Note: For example, to view data for a specific user and for a particular OAuth client IP address, select the user you are interested in under the TOP 10 USERS dashboard, and then select the IP address under the TOP 10 OAUTH CLIENT IP’s dashboard.

    As you drill down, you will be able to view customized combinations of data.

  12. To revoke an OAuth token, drill down one level into any of the fields on the dashboard. At the bottom of the screen, select the checkbox next to the OAuth tokens you wish to revoke.

  13. Select Revoke Selected Tokens, and then select OK.

  14. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

Use the Authorization Server Summary dashboard to track the overall health of your OAuth server. See the notes below to learn more about each category for which you can record data.

Value Functionality
Total Access Tokens This chart displays the total number of access tokens by the OAuth server.
Token Errors This chart displays the total number token errors from the OAuth server.
Unique Users This chart displays the total number of unique users in the OAuth configuration.
Unique Client Apps This chart displays the total number of unique client applications accessed by users.
Introspection Errors This chart displays the total number of introspection errors in the OAuth configuration.
TOKEN GENERATION REQUESTS OVER TIME This line chart displays requests for token generation over time.
TOP 10 OAUTH CLIENT IPs This chart displays the top ten Internet service providers that use the OAuth client configuration.
TOP 10 USERS This chart displays the top ten users who use the OAuth authorization server.
TOP 10 CLIENT APPS This chart displays the top ten client applications that use the OAuth authorization server.
USER PLATFORM DISTRIBUTION This chart displays the platform (such as operating system or mobile device) that distributes the OAuth service.
GEOLOCATION DISTRIBUTION This chart displays the country from which users are accessing the OAuth resource.

BIG-IQ Access users can view the Authorization Server Performance screen to track the health of an OAuth authorization server. If you previously configured a managed BIG-IP device running APM as an OAuth Authorization Server, you will be able to track the health of the server from this dashboard. You can also troubleshoot issues with token generation requests, and view data for token generation organized by grant type. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

The Authentication Server Summary screen shows several charts that you can use to track the health of your authorization server role. Controls on this screen work together so you can fine-tune the statistics display.

  1. Click Monitoring > DASHBOARDS > Access > Federation > OAuth > Authorization Server > Server Performance.

    BIG-IQ opens the Authorization Server Performance screen.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. From the AUTHORIZATION SERVER list, select an OAuth authorization server.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To view data for a different OAuth resource, make a selection from the Resource dropdown.

  8. For the line charts on this dashboard, select any of the metrics in order to remove or add each metric to the chart and view a customized data set.

The Authorization Server Performance screen shows several charts that you can use to track the health of your OAuth authorization server. See the notes below to learn more about each category for which you can record data.

Chart Functionality
OVERVIEW This chart summarizes performance statistics for requests that this OAuth authorization server processed.
AUTH CODE GRANT This chart displays statistics for the authorization code grants that this OAuth server processed.
IMPLICIT GRANT This chart displays statistics for the implicit grants that this OAuth server processed.
ROPC GRANT This chart displays statistics for the resource owner password credentials (ROPC) grants that this OAuth server processed.
TOKEN INTROSPECTION This chart displays statistics for the token introspection requests that this OAuth server processed.
Value Definition
Requests Displays the rate at which the total OAuth requests were received.
Auth Codes Issued Displays the rate at which the total authentication codes were received.
Tokens Issued Displays the rate at which the OAuth server issued tokens.
Refresh Tokens Issued Displays the rate at which the OAuth server issued refresh tokens for the authorization code and ROPC grant types.
Tokens Introspected Displays the rate at which the OAuth server processed successful token introspection requests.
Implicit Displays the rate at which the OAuth server processes implicit grants.
ROPC Displays the rate at which the OAuth server processes ROPC grants.
Failed Requests Displays the rate at which the OAuth server processed unsuccessful requests.

If you have configured a managed BIG-IP device to function as an OAuth Authorization server, you can use BIG-IQ to track the health of your OAuth tokens and view key token metrics. To do so, view the Token Summary screen. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

The Token Summary screen shows several charts that you can use to track the health of your OAuth tokens. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

  1. Click Monitoring > DASHBOARDS > Access > Federation > OAuth > Authorization Server > Tokens.

    BIG-IQ opens the Token Summary screen.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. From the AUTHORIZATION SERVER list, select an OAuth authorization server.

  5. From the GRANT TYPE list, select an OAuth grant type.

  6. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  7. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  8. To learn more details for the categories across the top of the page, select Total Access Tokens, Total Refresh Errors, Revoked Tokens, Expired Access Tokens, or Expired Refresh Tokens. BIG-IQ displays a screen with additional metrics for the selected category.

    Note: For example, if you are interested in viewing all expired access tokens resulting clients using Windows, select Expired Access Tokens then view the data for Windows under the chart titled PLATFORM DISTRIBUTION.

  9. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  10. To filter the list of tokens, select an option from the TOKEN FILTER dropdown menu. Select one of the following: Access Tokens Issued, Access Tokens Expired, Refresh Tokens Issued, or Refresh Tokens Expired.

  11. To revoke an OAuth token, use the list of OAuth tokens on the main Token Summary dashboard or drill down one level into any of the fields on the dashboard. At the bottom of the screen, select the checkbox next to the OAuth tokens you wish to revoke.

  12. Select Revoke Selected Tokens, and then select OK.

The Token Summary screen shows several charts that you can use to track the health of your OAuth authorization server tokens. See the notes below to learn more about each category for which you can record data.

Value

Functionality

Total Access Tokens

This chart displays the total number of access tokens in the OAuth configuration.

Total Refresh Tokens

This chart displays the total number of refresh tokens in the OAuth configuration.

Revoked Tokens

This chart displays the total number of tokens that were revoked by the OAuth provider.

Expired Access Tokens

This chart displays the total number of access tokens that expired.

Expired Refresh Tokens

This chart displays the total number of refresh tokens that expired.

User

This field displays the name of the user using the OAuth resource.

Client App

This field displays the name of the client application.

Access Token Issued

This field displays the date and time that this OAuth authorization server issued the token.

Access Token Expires

This field displays the date and time that a revoked token expired or that an active token is set to expire.

Access Token Count

This field displays the number of access tokens.

Access Token Status

This field displays one of these statuses:

  • ACTIVE: The status is active when the token is granted and remains active until an event occurs that changes the status.
  • EXPIRED: The status changes to expired only after a validate request has been attempted on an access token that has passed its expiration date.
  • REVOKED: The status changes to revoked when an administrator revokes the token.

Refresh Token Issued

This field displays the date and time that this OAuth authorization server issued the token.

Refresh Token Expires

This field displays the date and time that a revoked token expired or that an active token is set to expire.

Refresh Token Count

This field displays the number of refresh tokens.

Refresh Token Status

This field displays the OAuth token status, Active or Revoked.

HostName

This field displays the BIG-IP device hostname.

Cluster

This field displays the name of the device cluster.

User Agent

This field displays the name of the user agent.

Grant Type

This field displays the grant type as either authcode, implicit, or ROPC.

BIG-IQ Access users can configure a managed BIG-IP device to function as an OAuth client and resource server. With this configuration, customers can log on to using external OAuth accounts to gain access to the resources protected by the BIG-IP device provisioned with APM.

Once you have configured a BIG-IP device to act as an OAuth client, you can use BIG-IQ to monitor the health of the OAuth client. The Client Summary screen shows several charts that you can use to track the status of your OAuth client. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

From the Client Errors screen, you can view a full log of errors in the OAuth client configuration in order to troubleshoot issues with your OAuth client.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

You can use BIG-IQ to generate OAuth Client summary data. The Client Summary report shows several charts that you can use to track the health of your OAuth client. Controls on this screen work together so you can fine-tune the statistics display.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > OAuth > Client > Client Summary.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To view data for a different OAuth client, make a selection from the CLIENT dropdown list.

  5. To view data for a different grant type, make a selection from the GRANT TYPE dropdown list.

  6. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  7. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  8. To learn more details for the categories across the top of the page, select Token Requests, Token Errors, Unique Users, or Connectivity Errors. BIG-IQ displays a screen with additional metrics for the select this recorded category.

    Note: For example, to if you are interested in viewing all token requests initiated by a particular user, select Token Requests, and then view the data for the user you are interested in under the chart titled TOP 10 USERS. You can continue drilling down to further customize what displays on this screen.

  9. To view details for a specific session, click the ID under the Session ID column.

  10. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  11. Under the OAUTH CLIENT PERFORMANCE OVER TIME line chart, select any of the metrics in order to remove or add each metric for token generation.

  12. You can use the bar charts to drill down and generate a customized report. These dashboards are TOP 10 USERS, TOP 10 CLIENT IPs, TOP CLIENT PLATFORMS, and GEOLOCATION DISTRIBUTION.

    Note: For example, if you wanted to view data for a specific user with requests originating from California, select the user you are interested in from under the TOP 10 USERS dashboard and then select California under the GEOLOCATION DISTRIBUTION dashboard.

    You can continue drilling down further to view customized combinations of data.

  13. In the second level of the dashboards, you can view a list of sessions associated with OAuth client usage.

  14. To view details for a specific session, click the ID under the Session ID column.

The Client Summary screen shows several charts that you can use to track the health of your OAuth client. Each chart displays a different category of collected data.

Chart Functionality
Total Requests This chart displays the total number of client requests in the OAuth configuration.
Token Errors This chart displays the total number of token errors received by the OAuth client.
Unique Users This chart displays the total number of unique users in the OAuth configuration.
Connectivity Errors This chart displays the total number of connectivity errors in the OAuth configuration.
OAUTH CLIENT PERFORMANCE OVER TIME This chart displays a line chart for OAuth client performances over time.
TOP 10 USERS This chart displays the top ten users who have used the OAuth client over the specified time period.
TOP 10 CLIENT IPs This chart displays the top ten Internet Service Providers that use the OAuth client configuration.
PLATFORM DISTRIBUTION This chart displays the platform, such as operating system or mobile device, that distributes the OAuth service.
GEOLOCATION DISTRIBUTION This map displays the country in which the OAuth service is located.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

Use BIG-IQ Centralized Management to monitor OAuth client error logs. The Client Errors report shows a log of errors in the OAuth client configuration.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > OAuth > Client > Client Error Logs.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. View the list of error messages in the report. To view specific session details for one of the errors, click the ID under the Session ID column.

The Client Errors screen shows a list of errors in the OAuth client configuration. See the notes below to learn more about each field for which you can record data.

Field Functionality
Local Time This field displays the time and date the error message occurred.
HostName This field displays the hostname of the managed BIG-IP device that sent this error message.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level This field displays the log level of the error message.
Message This field displays the error message.

BIG-IQ Access users can configure a managed BIG-IP device to act as an OAuth client and resource server. Once you have done so, you can view the OAuth Resource Summary screen to track the health of your OAuth resource. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.

Use BIG-IQ Centralized Management to generate a summary report for your OAuth resource. The Resource Summary dashboard shows several charts that you can use to track the health of your OAuth resource. Controls on this screen work together so you can fine-tune the statistics display.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > OAuth > Resource.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To view data for a different OAuth resource, make a selection from the Resource dropdown.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To learn more details for the categories across the top of the page, select Token Validation Successes, Token Validation Errors, Unique Client IPs, or Connectivity Errors. BIG-IQ displays a screen with additional metrics for the selected category.

    Note: For example, to see resource usage originating from a specific client IP address, select Unique Client IPs, then view the data for the IP address you are interested in under the chart titled TOP 10 CLIENT IPs. You can continue drilling down to view even more customized reports.

  8. To view details for a specific session, click the ID under the Session ID column.

  9. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  10. Under the RESOURCE SERVER PERFORMANCE OVER TIME line chart, select any of the metrics in order to remove or add each metric to the chart for resource server performance.

  11. You can use the bar charts to drill down and generate a customized dashboard. These charts are TOP 10 CLIENT IPs, TOP CLIENT PLATFORMS, and GEOLOCATION DISTRIBUTION.

    Note: For example, to view data for a specific client IP address with requests originating from Seattle:

    1. On the TOP 10 CLIENT IPs chart, select the IP address you are interested in.
    2. On the map in the GEOLOCATION DISTRIBUTION chart, select Seattle. Once you drill down, you will be able to view customized combinations of data for the selected Seattle IP address.

The Resource Summary screen shows several charts that you can use to track the health of your OAuth resource. Each chart displays a different category of collected data.

Chart Functionality
Token Validation Successes This chart displays the total number of successful token validation by the OAuth resource server.
Token Validation Errors This chart displays the total number validation errors from the OAuth resource server.
Unique Client IPs This chart displays the total number of unique client IPs in the OAuth configuration.
Connectivity Errors This chart displays the total number of connectivity errors on the OAuth resource server.
RESOURCE SERVER PERFORMANCE OVER TIME This chart displays a line chart for resource server performances over time.
TOP 10 CLIENT IPs This chart displays the top ten client IP addresses that use the OAuth client configuration.
PLATFORM DISTRIBUTION This chart displays the operating system for the user’s machine that distributes the OAuth service.
GEOLOCATION DISTRIBUTION This chart displays the country in which the user is located.

BIG-IQ Access users can configure a managed BIG-IP device with APM provisioned to act as a SAML service provider (SP). Once you have done so, use the SAML SP Summary dashboard to track the health of your SAML SP resource. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a managed BIG-IP device with SAML provisioned can provide data for SAML reports.

Use BIG-IQ Centralized Management to generate a summary report for SAML Service Provider (SP) resources. The SP Summary report shows several charts that you can use to track the health of your SAML SP resource. Controls on this screen work together so you can fine-tune the statistics display.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > SAML > SP > SP Summary.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To view data for a different SAML service provider, make a selection from the SP dropdown list.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To learn more details for the categories across the top of the page, select Assertions Success and Assertions Failed. A screen appears with additional metrics for this recorded category.

    Note: For example, if you are interested in viewing all successful assertions from a particular OAuth service provider, select Successful Assertions. Then select a service provider under the chart titled TOP 10 SPs WITH SUCCESSFUL ASSERTIONS. Continue drilling down for a more specific report.

  8. To view details for a specific session, click the ID under the Session ID column.

  9. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  10. Under the IDP ASSERTIONS OVER TIME line chart, select any of the metrics in order to remove or add each metric for the IdP assertion chart.

  11. You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 IDPs WITH SUCCESSFUL ASSERTIONS, TOP 10 CLIENT IPs, TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS, and TOP 10 IDPs WITH FAILED ASSERTIONS.

    Note: For example, if you wanted to view data for a specific user and for a particular OAuth client IP address, select the user you are interested in from under the TOP 10 USERS dashboard and then select the IP address under the TOP 10 OAUTH CLIENT IPs dashboard.

    As you drill down, you will be able to view customized combinations of data.

The SP Summary screen shows several charts that you can use to track the health of your SAML SP resource. Each chart displays a different category of collected data.

Chart Functionality
Assertions Success This chart displays the number of successful SP assertions.
Assertions Failed This chart displays the total number of failed SP assertions.
SP ASSERTIONS OVER TIME This chart displays a line chart for SP assertions over time.
TOP 10 IdPs WITH SUCCESSFUL ASSERTIONS This chart displays the top ten IdPs with successful assertions.
TOP 10 IDPs WITH FAILED ASSERTIONS This chart displays the top ten IdPs with failed assertions.
TOP 10 CLIENT IPs This chart displays the top ten Client IP addresses that use SP assertions.
TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS This chart displays the top subject values with successful assertions.

BIG-IQ Access users can monitor SAML Service Provider assertion data using the SP Assertions dashboard. The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a BIG-IP device with SAML provisioned on it can provide data for SAML reports.

The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. Controls on this screen work together so you can fine-tune the statistics display.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > SAML > SP > SP Assertions Reports.

    The SP Assertions screen opens, displaying a table with assertion information.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To view data for a specific SAML service provider, select one from the SP dropdown list.

    View the list of SP assertions in the table.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To view details for a specific session, click the ID under the Session ID column.

The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. See the notes below to learn more about each field for which you can record data.

Field Functionality
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Assertion Time This field displays the time and date when the SP assertion occurred.
Name This field displays the SP service.
User Name This field displays the username attempting to sign on with Single Sign-ON (SSO).
HostName This field displays managed BIG-IP device hostname.
Platform This field displays the operating system of the client’s machine.
Cluster This field displays the cluster attached to the SP service.

BIG-IQ Access users can generate SAML SP error reports to view a full length log for all error messages originating from a managed BIG-IP device serving as a SAML SP. To do so, use the SAML SP Error Report screen in BIG-IQ. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a BIG-IP device with SAML provisioned on it can provide data for SAML reports.

The SP Errors screen shows several charts that you can use to track the health of your SAML SP errors. Controls on this screen work together so you can fine-tune the statistics display.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > SAML > SP > SP Error Reports.

    The SP Error Reports screen opens, displaying the error logs.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To view data for a specific SAML service provider, select one from the SP dropdown list.

    View the list of service provider errors in the table on the dashboard.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. View the list of service provider errors in the table on the dashboard.

  8. To view details for a specific session, click the ID under the Session ID column.

The SP Errors screen shows several charts that you can use to track the health of your SAML SP errors. See the notes below to learn more about each field for which you can record data.

Field Functionality
Local Time This field displays the time and date the error message occurred.
HostName This field displays the hostname of the managed BIG-IP device from which this error message originated.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level This field displays the log level of the error message.
Message This field displays the error message.

BIG-IQ Access users can configure managed BIG-IP devices with APM provisioned to act as a SAML Identity Provider (IdP) for Software as a Service (SaaS) applications. Configure managed BIG-IP devices as a SAML IdP to enable Single-Sign On to common applications. Once you have configured a BIG-IP device as an IdP, use BIG-IQ to track the health of your SAML IdP resource. Using the IdP Summary dashboard, you can view a variety of metrics to monitor SAML assertions and IdP errors.

Data appears on this dashboard when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a managed BIG-IP device with SAML provisioned can provide data for SAML reports.

Use BIG-IQ Centralized Management to generate a SAML Identity Provider report. The IdP Summary report shows several charts that you can use to track the health of your SAML IdP resource.

  1. Navigate to Monitoring > DASHBOARDS > Access > Federation > SAML > IdP > IdP Summary.

    The IdP Summary screen opens, displaying a dashboard with summary information.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To learn more details for the categories across the top of the page, select Assertions Success and Assertions Failed. A screen appears with additional metrics for this recorded category.

    Note: For example, if you are interested in viewing all successful assertions from a particular OAuth identity provider, select Successful Assertions. Then select an identity provider under the chart titled TOP 10 IDPs WITH SUCCESSFUL ASSERTIONS. Continue drilling down for a more customized report.

  8. To view details for a specific session, click the ID under the Session ID column.

  9. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  10. Under the IDP ASSERTIONS OVER TIME line chart, select any of the metrics in order to remove or add each metric for the IdP assertion chart.

  11. You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 SPs WITH SUCCESSFUL ASSERTIONS, TOP 10 USERS, TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS, and TOP 10 SPs WITH FAILED ASSERTIONS.

    Note: For example, if you wanted to view data for a specific user and for a particular client IP address, select the user you are interested in from under the TOP 10 USERS dashboard and then select the IP address under the TOP 10 CLIENT IP’s dashboard.

    As you drill down, you will be able to view customized combinations of data.

The IdP Summary screen shows several charts that you can use to track the health of your SAML IdP resource. Each chart displays a different category of collected data.

Chart Functionality
Assertions Success This chart displays the total number of successful IdP assertions.
Assertions Failed This chart displays the total number of failed IdP assertions.
IDP ASSERTIONS OVER TIME This chart displays a line chart for IdP assertions over time.
TOP 10 SPs WITH SUCCESSFUL ASSERTIONS This chart displays the top ten SPs with successful assertions.
TOP 10 USERS This chart displays the top ten users who have attempted to sign in using a SAML IdP.
TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS This chart displays the top subject values with successful assertions.
TOP 10 IDPs WITH FAILED ASSERTIONS This chart displays the top ten IdPs with failed assertions.

BIG-IQ Access users can monitor SAML Identity Provider assertion data using the IdP Assertions dashboard. The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdP assertions. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a managed BIG-IP device with SAML provisioned on it can provide data for SAML reports.

The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdP assertions. Controls on this screen work together so you can fine-tune the statistics display.

  1. Click Monitoring > DASHBOARDS > Access > Federation > SAML > IdP Assertions

    The IdP Assertions screen opens, displaying a table with assertion information.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. View a list of IdP assertions in the dashboard for the selected SAML identity provider.

  8. To view details for a specific session, click the ID under the Session ID column.

The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdPs assertions. See the notes below to learn more about each field for which you can record data.

Field Functionality
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Assertion Time This field displays the time and date when the SP assertion occurred.
Name This field displays the name of the IdP service.
User Name This field displays the username of the person using the managed BIG-IP device.
HostName This field displays managed BIG-IP device hostname.
Platform This field displays the operating system of the client’s machine.
Cluster This field displays the cluster attached to the IdP service.

BIG-IQ Access users can generate SAML IdP error reports to view a full length log for all error messages originating from a managed BIG-IP device serving as a SAML IdP. To do so, use the SAML IdP Error Report screen in BIG-IQ. Data appears on the dashboard when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a managed BIG-IP device with SAML provisioned on it can provide data for SAML reports.

The IdP Errors screen shows several charts that you can use to track the health of your SAML IdP errors. Controls on this screen work together so you can fine-tune the statistics display.

  1. Select Monitoring > DASHBOARDS > Access > Federation > SAML > IdP > IdP Error Report.

    The IdP Errors screen opens, displaying a table with reported errors.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.

    View a list of IdP errors in this dashboard.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. To view details for a specific session, click the ID under the Session ID column.

The IdP Errors screen shows several charts that you can use to track the health of your SAML IdP errors. Each chart displays a different category of collected data.

Value Functionality
Local Time This field displays the time and date the error message occurred.
HostName This field displays the hostname of the managed BIG-IP that generated this error message.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level This field displays the log level of the error message.
Message This field displays the error message.

Before you can display statistics in the SWG analytics screen, you must have the following configured:

  • A BIG-IQ data collection device configured for the BIG-IQ device

  • The BIG-IP device located in your network and running a compatible software version

  • To view the SWG Dashboard, statistics collection on the BIG-IP device should be enabled.

    Note: For BIG-IP devices running versions 13.1.0.5 or later, enabling the BIG-IP device’s statistics collection may affect the information that appears in the Secure Web Gateway Summary screen (Monitoring > DASHBOARDS > Access > Secure Web Gateway > Secure Web Gateway Summary).

  • For BIG-IP devices running versions 13.1.0.5, or later, you must have AVR provisioned on your BIG-IP device.

View statistics for all traffic managed with Secure Web Gateway (SWG) to ensure that your configured access profile properly secures the users within your network.

  1. Click Monitoring > DASHBOARDS > Access > SWG.

    The screen displays the SWG analytics screen. By default, the screen displays statistics from the past hour. You can adjust the time settings using the controls found at the top of the screen.

  2. To display events that correspond with the chart timeline, click Events.

    Events that occurred within the selected time period are displayed in the chart. You can select the event icons within the chart to display event details.

  3. Expand the dimensions found at the far right of the screen to view additional data.

  4. Filter displayed data by dimension objects:

    1. To filter data by one or more BIG-IP devices, expand BIG-IP Host Names or BIG-IP Blade Numbers and select one or more dimension objects.

    2. To filter data by traffic or security settings (e.g. a URL category and a corresponding action) expand the remaining dimensions and select one or more dimension objects.

      Note: You can select objects from multiple dimensions. Once you select an object, only dimensions with corresponding data are displayed in the charts and dimensions

Briefly explain the outcome of having completed this task. This element is optional, but recommended.

To edit your SWG settings go to Configuration > ACCESS > Access Groups and select the Access group name. For more information about Access group configuration, refer to the BIG-IQ Centralized Management: Access on support.f5.com for configuration information.

The BIG-IQ Centralized Management Application Summary dashboard displays information regarding the applications linked to the system.

  1. At the top of the screen, click Monitoring.

  2. On the left, select DASHBOARDS > Access > Application Summary.

The Application Summary screen opens, showing detailed information and charts for specific applications.

You can monitor your user base by viewing the BIG-IQ Centralized Management Access user dashboard for data on specific users. The system displays which users created the most sessions, were denied the most sessions, and had the longest total session duration. The administrator can enter a specific user name to get the following details for the user:

  • The user login locations on a world map
  • The total sessions, denied sessions, and session duration
  • The Access denied sessions.
  • The top authentication failures, including AD Auth and LDAP only
  • The device type users used to log into the system
  • The reason the system terminated the session
  • The login history showing the success and failures over time
  • The most accessed applications
  • The most accessed URLs
  • The login failure attempts over time, sorted by the reason
  • The client session duration over time
  • The Access denied reason over time

You can monitor your applications by viewing the BIG-IQ Centralized Management Access user dashboard for data on which applications are linked to the BIG-IQ Access component. The system displays the top applications used and the application usage time. Administrators can expand the GUI for a specific application and view the following information:

  • The application access history
  • The users who use the application the most
  • The access history
  • The world map, showing where the user is access the application

Logging nodes are highly available, but it is still possible for them to become unavailable. This could occur, for example, if all logging nodes are on devices in the same rack in a lab, and the power to the lab shuts down.

You can configure the BIG-IQ system to log information about BIG-IQ and Secure Web Gateway events and send the log messages to remote high-speed log servers.

When configuring remote high-speed logging of events, it is helpful to understand the objects you need to create and why, as described here:

Object Reason
Pool of remote log servers Create a pool of remote log servers to which the BIG-IP system can send log messages.
Destination (unformatted) Create a log destination of Remote High-Speed Log type that specifies a pool of remote log servers.
Destination (formatted) If your remote log servers are the ArcSight, Splunk, or Remote Syslog type, create an additional log destination to format the logs in the required format and forward the logs to a remote high-speed log destination.
Publisher Create a log publisher to send logs to a set of specified log destinations.
Log Setting Add event logging for the APM system and configure log levels for it or add logging for URL filter events, or both. Settings include the specification of up to two log publishers: one for access system logging and one for URL request logging.
Access profile Add log settings to the access profile. The log settings for the access profile control logging for the traffic that comes through the virtual server to which the access profile is assigned.

Before creating a pool of log servers, gather the IP addresses of the servers that you want to include in the pool. Ensure that the remote log servers are configured to listen to and receive log messages from the BIG-IP system.

Create a pool of remote log servers to which the BIG-IP system can send log messages.

  1. At the top of the screen, click Configuration.

  2. On the Main tab, click Local Traffic > Pools.

    The Pool List screen opens.

  3. Click Create.

    The New Pool screen opens.

  4. In the Name field, type a unique name for the pool.

  5. Using the New Members setting, add the IP address for each remote logging server that you want to include in the pool:

    1. Type an IP address in the Address field, or select a node address from the Node List.

    2. Type a service number in the Service Port field, or select a service name from the list.

      Note: Typical remote logging servers require port 514.

    3. Click Add.

  6. Click Finished.

Before you can create a new log destination, you must have configured a remote log server to send the logs to.

Use this screen to create a new log destination for a managed device.

Create a log destination to specify that log messages are sent to a remote log server.

  1. At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Destinations.

    The Log Destinations screen displays a list of the log destinations that are defined on this device.

  2. To create a new log destination, click Create.

    The New Log destination screen opens so you can define the settings you want for this destination.

  3. In the Name field, type in a name for the log destination you are creating.

  4. For Type, select the kind of destination you are creating.

    Depending on the selection you make, additional controls are displayed.

  5. Specify the additional settings needed to suit the requirements for this log destination. The fields required to create a new log destination depend on the type you choose. BIG-IQ denotes required fields using an amber box. You can also determine whether you have completed all of the required fields by noting whether the Save & Close button is enabled.

    Note: Except for the Devices and Device Specific settings, the parameters on this screen perform the same function as they do when you configure a log destination on a BIG-IP device. For details about the purpose or function of a particular setting, refer to the BIG-IP reference information on support.f5.com. From the BIG-IP Knowledge Center, select the BIG-IP LTM module and the software version you have installed; then select the appropriate guide. For example, information about the log destination parameters for BIG-IP version 13.0 is provided in the External Monitoring of BIG-IP Systems: Implementations, Version 13.0 guide.

  6. When you create a Log Destination and select a type of IPFIX or Remote High-Speed Log, you need to specify which devices to associate this destination with. When you create a Log Destination and select a type of Management Port you can specify device specific settings or, if no device specific settings are defined, the base configuration settings are used for any device associated with this log destination.

    Note: For additional detail on device-specific log destination types, refer to What is a device specific log destination? in the F5 BIG-IQ Centralized Management: Local Traffic & Network Implementations guide on support.f5.com.

    • If you have a lot of devices that you need to associate with this log destination and want to automate the process:
      1. Use the steps below to specify one device and then click Save.
      2. Associate this log destination with the log publishers that are pinned to your managed devices.
      3. Come back and edit this log destination. A Find Relevant Devices button displays. You can use this button to let BIG-IQ assemble a list of devices. BIG-IQ finds the BIG-IP devices that this destination can be deployed to. You can use the list to create a device-specific instance of this destination for each BIG-IP.
      4. Click Save to add the listed devices to the Device Specific list.
    • To specify the devices for this log destination manually:
      1. Select the device you want this destination to use
      2. If you are creating an IPFIX or Remote High-Speed Log destination log, select the pool that you want each device to use.
      3. Use the
        button to add additional devices to the list.
      4. Use the
        button to remove a device from the list.
      5. Click Save to add the listed devices to the Device Specific list. Devices you select for this log destination are added to the Device Specific list.

    Note: Click on a device name in the Device Specific list to edit settings for that device. Bear in mind though that changes you make to one device do not change the settings for other devices, or for the base configuration for the log destination.

  7. Click Save & Close.

    The system creates the new log destination with the settings you specified.

Changes that you make are made only to the pending version. The pending version serves as a repository for changes you stage before deploying them to the managed device. Object settings for the pending version are not the same as the object settings on the actual BIG-IP device until they are deployed or discarded.

When you finish specifying the settings for this log destination, the next step is to evaluate and then deploy the changes to the target device. Until you deploy the changes stored in the pending version, objects on the managed device are not changed.

Before you can create a new log publisher, configure a log destination with a pool of remote log servers so you can assign it to your publisher as you create it.

Log publishers specify log destinations that BIG-IP devices can send their log messages to.

  1. At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Publishers.

    The screen displays a list of the Log Publishers that are defined on this device.

  2. To create a new log publisher, click Create.

    The New Log Publisher screen opens so you can define the settings you want for this publisher.

  3. In the Name field, type in a name for the log publisher you are creating.

  4. Select the Log Destinations for this publisher.

    1. Select a destination type from the Available list.

      The list of destinations displays only the type you selected.

    2. Select one or more destinations from the Available list.

    3. Move the selected destinations to the Selected list.

      If you are using a formatted destination, select the destination that matches your log servers, such as Remote Syslog, Splunk, or ArcSight.

  5. Specify the additional settings needed to suit the requirements for this log publisher.

    The parameters on this screen are optional and perform the same function as they do when you configure a log publisher on a BIG-IP device.

    Note: For details about the purpose or function of a particular setting, refer to the BIG-IP reference information on support.f5.com. From the BIG-IP Knowledge Center, select the BIG-IP LTM module and the software version you have installed; then select the appropriate guide. For example, information about the log publisher parameters for BIG-IP version 13.0 is provided in the External Monitoring of BIG-IP Systems: Implementations guide.

  6. Click Save & Close.

    The system creates the new log publisher with the settings you specified.

Changes that you make are made only to the pending version. The pending version serves as a repository for changes you stage before deploying them to the managed device. Object settings for the pending version are not the same as the object settings on the actual BIG-IP device until they are deployed or discarded.

When you finish specifying the settings for this log publisher, the next step is to evaluate and then deploy the changes to the target device. Until you deploy the changes stored in the pending version, objects on the managed device are not changed.

Create log settings to enable event logging for access system events or URL filtering events or both. Log settings specify how to process event logs for the traffic that passes through a virtual server with a particular access profile.

  1. At the top of the screen, select Configuration, then on the left side of the screen, click ACCESS > Access Groups.

  2. Click the name of an Access group.

    A new screen displays the group’s properties.

  3. Click EVENT LOGS SETTINGS > Create.

  4. Type a name for the name for the log setting.

  5. In the SSO Configuration Description field, type a descriptive text for the configuration.

  6. For Access System Logs, click the check box to specify a publisher for Access system logs and log levels.

  7. For Access Logs Publisher, select a log publisher.

  8. For the system log types, beginning with Access Policy and ending with ADFS Proxy, from the dropdown lists, select a log level. The default is Notice.

  9. For URL Request Logs, click the check box to select a publisher for the logs and specifies the URL requests to log based on whether the request was blocked or allowed.

  10. For URL Request Logs Publisher, select a log publisher.

  11. For Log Allowed Events, click the check box to log request data when a user tries to access a URL that the URL filter allows.

  12. For Log Blocked Events, click the check box to log request data when a user tries to access a URL that the URL filter blocks.

  13. For Log Confirmed Events, click the check box to log request data when a user confirms a request for access to a URL for which the URL filter requires confirmation.

  14. Click Save & Close.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a device with SWG provisioned on it can provide data for Secure Web Gateway reports.

You can create SWG reports for Access groups, clusters (in Access groups), or devices that you select from the Access groups and clusters (in Access groups) on the BIG-IQ system.

  1. At the top of the screen, click Monitoring.

  2. Monitoring > DASHBOARDS > Access > Secure Web Gateway > Secure Web Gateway Summary.

    A Summary report (for all devices and a default timeframe) starts to generate and display.

  3. From the left, select any report that you want to run.

  4. From the ACCESS GROUP/DEVICE list at upper left, select Managed Devices or select one or more of these options:

    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  5. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  6. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Only a device with SWG provisioned on it can provide data for SWG reports.

From the Summary report, the initial display includes graphs that summarize the report data. You can get more detailed information by clicking a bar or a point on a graph to see additional graphs and tables with supporting entries.

  1. At the top of the screen, click Monitoring.

  2. On the left, select DASHBOARDS > Access > Secure Web Gateway.

    The Summary starts to generate and display. A timeline and some summaries display across the top of the screen. Graphs display under the summaries. Each graph provide different views of the data.

  3. Click any bar in a graph on the display to get more information.

    Additional graphs provide different views of the data, and supporting data displays in a table at the bottom of the screen.

  4. If more details are available, click the bars in the graphs to display them.

  5. Scroll down to the table to view the supporting data.

BIG-IQ Centralized Management offers advanced monitoring and troubleshooting capabilities for connectivity and VPN use cases. You may use the remote access monitoring functionality to gain visibility into the behavior of VPN traffic, as well as to view the log of errors associated with failed connections. With remote access monitoring, you can maintain a high-level visibility for network access requests and session data for all users accessing the network through Access policies.

Navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Summary

View data for Network Access usage summary. From this report, you can:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
User interface control Functionality
Active Users Displays the total number of users actively connected to a session. Click Active Users to open the Active Users screen, which displays charts describing the top 1,000 users and the top 1,000 locations.
Active Connections Displays the total active connections. Click Active Connections to open the Active Connections screen, which displays charts describing the top 1,000 users and the top 1,000 locations.
Total Sessions Displays the total number of sessions established.
Total Reconnects Displays the number of times users tried to reestablish a session. Click Total Reconnects to open the Total Reconnects screen, which displays charts describing reconnects.
Network Access Session Errors Displays the total number of errors that occurred during network access sessions. Click Network Access Session Errors to open the Connectivity Errors screen, which displays a list of connectivity errors. Click Session ID to display detailed session details and session variable information.

User interface control

What does this do?

NETWORK ACCESS RECONNECTS OVER TIME

Displays a chart of the network access reconnects over time.

TOP 10 USERS BY RECONNECTS

Displays the top ten users with the most reconnects. Select a user from the bar chart to display detailed information about the user.

RECONNECTS GEO DISTRIBUTION

Displays the geographical locations from which the reconnects originate. Click the locations on the map to display detailed information about the country from which the reconnect originated.

CLIENTS IPS BY RECONNECTS

Displays the IP address of the client devices from which the reconnects originate. Select a client from the bar chart to display the types of client operating systems.

User interface control What does this do?
Sessions Use this tab to view charts displaying the sessions over time in the network access.
Connections Use this tab to view charts displaying the connections over time in the network access.
Bytes Transferred Use this tab to view charts displaying the bytes transferred over time in the network access.

Chart

What does this do?

Chart Title

Each chart displays a title that identifies the statistic plotted on that chart.

NETWORK ACCESS SESSIONS OVER TIME

Displays the network access sessions over time.

TOP 10 USERS BY SESSIONS

Displays the users with the most sessions and the number of sessions per user. Select a user from the list to display detailed session information for that user.

TOP 10 USERS BY RECONNECTS

Displays the users with the most reconnects and the number of reconnects per user. Select a user from the list to display detailed reconnect information for that user.

SESSIONS GEO DISTRIBUTION

Displays the geographical locations from which the sessions originate. Click the locations on the map to display detailed information about the country from which the session originated.

TUNNEL TYPES BY SESSIONS

Displays the types of tunnels used by all sessions and the number of tunnels used. Click the ring chart to display detailed information about the tunnel types.

TOP 10 CLIENTS IPS BY SESSIONS

Displays the IP addresses of the top client systems from which the sessions originate and the number of sessions per client. Select a client from the bar chart to display detailed session information for that client.

CLIENT OS BY SESSIONS

Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.

Chart

What does this do?

Chart Title

Each chart displays a title that identifies the statistic plotted on that chart.

NETWORK ACCESS CONNECTIONS OVER TIME

Displays the network access connections over time.

TOP 10 USERS BY CONNECTIONS

Displays the users with the most connections and the number of connections per user. Select a user from the list to display detailed connections information for that user.

TOP 10 USERS BY RECONNECTS

Displays the users with the most reconnects and the number of reconnects per user. Select a user from the list to display detailed reconnect information for that user.

CONNECTIONS GEO DISTRIBUTION

Displays the geographical locations from which the connections originate. Click the locations on the map to display detailed information about the country from which the connection originated.

TUNNEL TYPES BY CONNECTIONS

Displays the types of tunnels used by all connections and the number of tunnels used. Click the pie chart to display detailed information about the tunnel types.

TOP 10 CLIENTS IPS BY CONNECTIONS

Displays the IP addresses of the top client systems from which the connections originate and the number of connections per client. Select a client from the bar chart to display detailed connection information for that client.

CLIENT OS BY CONNECTIONS

Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.

Chart

Functionality

Chart Title

Each chart displays a title that identifies the statistic plotted on that chart.

NETWORK ACCESS BYTES TRANSFERRED OVER TIME

Displays the bytes transferred over time in the network access.

TOP 10 USERS BY BYTES TRANSFERRED

Displays the users with the most bytes transferred and the size of the transfers. Select a user from the list to display detailed information for that user.

BYTES TRANSFERRED GEO DISTRIBUTION

Displays the geographical locations from which the bytes originate. Click the locations on the map to display detailed information about the country from which the bytes originated.

TOP 10 CLIENTS IPS BY BYTES TRANSFERRED

Displays the IP addresses of the top client systems that transferred bytes of information and the size of the transfers. Select a client from the bar chart to display detailed bytes transferred information for that client.

CLIENT OS BY BYTES TRANSFERRED

Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.

BIG-IQ Centralized Management allows you to monitor and troubleshoot network access requests by all clients attempting to join your network. You can use the aggregated data on the following page to understand the overall success of network access requests, and to view the amount of VPN traffic at any given moment or over a period of time.

To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Performance.

Within BIG-IQ, you can view data for Network Access performance. From this report, you may:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both.

  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographic location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.

  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. You can adjust each end of the control. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.

  • Select CSV Report to download a CSV file of this data to your local machine.

  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.

Term

Definition

THROUGHPUT OVER TIME

Displays the throughput to and from the client over time.

ACTIVE CONNECTIONS OVER TIME

Displays the number of active network access sessions over time by all users.

NEW CONNECTIONS OVER TIME

Displays the new network connections over time from all users.

From BIQ-IQ, you may view a report of all of the reconnections to your network through your VPN. You may use this page to troubleshoot connectivity issues with your VPN or to determine if a connectivity issue lies on the client-side.

To do this, view a report for Network Access reconnections. Access this page at Monitoring > DASHBOARDS > Remote Access > Network Access > Network Access Recconnect Detail. From this page, you can:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
  • Add or remove the Client Application field by clicking the settings icon on the right and selecting or deselecting Client Application report.

View reconnect detail properties:

User interface control Functionality
Local Time Displays the local timestamp when the user reconnected to the network access connection.
Hostname Displays the BIG-IP system from which the network access connection originates.
Cluster Displays the BIG-IP APM cluster.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
User Name Displays the username of the reconnecting user.
Client IP Displays the IP address of the client device used for the reconnect.
Client OS Displays the operating system of the client device used for the reconnect.
Country Displays the country where the reconnect originates.
State Displays the geographical state where the reconnect originates.
Continent Displays the continent where the reconnect originates.

You may use BIG-IQ Centralized Management to log all error messages received for every failed network access request in order to facilitate troubleshooting efforts for an end-user or to understand trends with connectivity issues and come to a resolution. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Errors

View all details for Network Access errors. From this page, you can:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both.
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Chart title Functionality
Local Time Displays the local timestamp when error occurred.
Hostname Displays the BIG-IP system from which the network access error occurred.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
Error Message Displays the error message associated with this network access failure.
User Name Displays the username of the the user associated with the error.
Client IP Displays the IP address of the client device where the error occurred.
Client OS Displays the operating system of the client device where the error occurred.
Country Displays the country where the error occurred.

BIG-IQ provides you with the ability to monitor the frequency of network access requests, as well as to drill-down on the data for all of these requests. You may request reports on traffic throughput for a specific user, and you may track the geographical location of all of the network access requests in order to prevent and spot session takeover or unauthorized network access. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Usage.

From this page, you can:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Chart title Functionality
User Name Displays the usernames of the top users by usage.
Total Connections Displays the total number of network access connections.
Total Bytes In Displays the total number of bytes received by the network access.
Total Bytes Out Displays the total number of bytes sent out by the network access.
Total Bytes Transferred Displays the total number of sent and received bytes.
Total Bytes Transferred Displays the total number of sent and received bytes.
Total Duration Displays the total duration when the network access connections for a user were active. When the user has multiple active connections at the same time, the total duration is the sum of the duration of those two connections.
Distinct Locations Displays the number of unique locations from where the network access usage originates.

View network access usage for the top 1000 locations:

Country

Displays the countries from where the network access usage originates.

State

Displays the states in the countries from where the network access usage originates.

Total Connections

Displays the total number of network access connections.

Total Bytes In

Displays the total number of bytes received by the network access.

Total Bytes Out

Displays the total number of bytes sent out by the network access.

Total Bytes Transferred

Displays the total number of sent and received bytes.

Total Duration

Displays the total duration when the network access connections for a user were active. When the user has multiple active connections at the same time, the total duration is the sum of the duration of those two connections.

Note: The date filter is applied on the connection start time. If you select a date range that starts after the network access connection was established, BIG-IQ does not display the connection record because date range selected does not include connection state time.

BIG-IQ allows you to separately monitor portal access network traffic and network access requests that stem from BIG-IP Edge Client. To monitor data on portal access requests and to receive reports on this data, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Portal Access.

View data for Portal Access sessions. From this report, you can:

  • Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • View the number of client requests, cache hits, and cache misses over time in the Portal Access chart.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Column Title Functionality
Local Time Displays the local timestamp when the system generates a report every ten minutes.
Client Requests / min Displays the number of client requests per minute.
Cache Hits / min Displays the number of cache hits per minute.
Cache Misses / min Displays the number of cache misses per minute.

You may use BIG-IQ to collect data on virtual desktop sessions in order to troubleshoot connectivity issues and view trends over time or for a certain time period. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > VDI Summary.

From this report, you can:

  • Generate reports with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
  • Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
  • View the number of client requests, cache hits, and cache misses over time in the Portal Access chart.
  • Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
  • Select CSV Report to download a CSV file of this data to your local machine.
  • Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.

Chart or list

Functionality

VDI SESSIONS OVERTIME

Displays a chart containing data points for VDI sessions by network users over time.

TOP 10 USED VDI APPLICATIONS

Displays the most frequently used VDI applications for remote access users.

Top 50 VDI Applications by Request count

Displays a list containing the top 50 most requested VDI applications.

BIG-IQ Centralized Management allows users to monitor data for all session requests managed by Access Policy Manager (APM). Use BIG-IQ to create a summary report for all sessions, as well as to view individual session details and log messages.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

You can create session reports for any managed BIG-IP device with an APM configuration that has been discovered on the BIG-IQ system, whether or not the device is a member of an Access group. To create a report, you can select any combination of Access groups, clusters, and devices.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Sessions Summary

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, and <Device name>).

    • All Devices Includes Access devices that are currently managed, and Access devices that were managed at one time but are not managed now. (A managed device is one that has been discovered with the APM service configuration.)
    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> - Select to include all devices in the Access group.
    • <Cluster display name> - Select to include the devices in the cluster.
    • <Device name> - Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. To view details for a specific session, click the ID under the Session ID column.

  7. Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.

  8. Select Close.

BIG-IQ Access allows you to monitor APM session data from the Sessions Summary dashboard. From this page, you can generate customizable and dynamic reports to monitor top-level content for all sessions. See the notes below to learn more about each category for which you can record data.

Value Functionality
Local Time Displays the date and time that the session was created.
Hostname Displays the managed BIG-IP device name.
Cluster Displays the High Availability (HA) cluster associated with the session.
Session ID Click the Session ID to open the Session Details screen, displaying session details and session variables.
Session Duration Displays the duration of time when the session was active.
Session Termination Displays the local timestamp when the session was terminated.
Active Displays a green dot if the session is active.
User Name Displays the logon name used to start a session.
Virtual IP Displays the IP address of the virtual server where the session started.
Client IP Displays the IP address of the client that started the session.
Client OS Displays the operating system of the client that started the session.
IP-Reputation For a connection attempted from an IP address that exists in the IP reputation database on a device, specifies the category of IP reputation, or, Unknown when IP intelligence is not enabled on the BIG-IP device.
Continent Displays the continent on which the client is located.
Country Displays the country in which the client is located.
State Displays the state or province in which the client is located.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

You can stop currently active sessions on BIG-IP devices, using the Active sessions report on the BIG-IQ system.

  1. Click Monitoring > DASHBOARDS > Access > Sessions > Active.

    The screen displays a list of active sessions for all devices.

  2. To display sessions for particular devices, groups, or clusters only, select them from the ACCESS GROUP/DEVICE list at upper left.

    The screen displays the active sessions for the selected devices.

  3. To stop specific sessions only, select the sessions that you want to end and click Kill Selected Sessions.

  4. To stop all sessions, click Kill All Sessions.

BIG-IQ Access allows you to monitor APM session data for all active sessions. From this page, you can generate customizable and dynamic reports to monitor top-level content for all active sessions. See the notes below to learn more about each category for which you can generate data.

Value Functionality
Local Time Displays the date and time that the session was created.
Hostname Displays the managed BIG-IP device name.
Cluster Displays the high availability cluster associated with the session.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
User Name Displays the logon name of the user who initiated this session.
Virtual IP Displays the IP address of the virtual server where the session started..
Client IP Displays the IP address of the client that started the session.
IP Reputation For a connection attempted from an IP address that exists in the IP reputation database on a device, specifies the category of IP reputation, or, when IP intelligence is not enabled on the device, Unknown.
Continent Displays the country in which the client is located.
State Displays the state or province in which the client is located.
Access Profile Displays the access profile used by the BIG-IP device for this session.

Using BIG-IQ Centralized Management, you can monitor all session activity originating from the Access profiles (also known as per-session policies) that you configured. The session count displayed in BIG-IQ includes both established and failed sessions. Use this report to determine which Access profiles are being used most frequently by your users in order to determine or troubleshoot resource allocation.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

With BIG-IQ, you can generate reports for sessions, grouped by the Access profile used, in order to gain information about which Access profiles are being used most heavily. The session counts displayed on the dashboard include both established and failed sessions.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Access Profile Usage.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. Under Top 5 Access Profiles By Session Count, select an Access profile from the top right corner of the chart to add or remove an Access profile from view.

BIG-IQ Access allows you to monitor session data, grouped by Access profile used, from the Access Profile Usage dashboard. The session counts displayed on this dashboard include established and failed sessions. See the notes below to learn more about each category for which you can record data.

Value or Chart Title Functionality
TOP 5 ACCESS PROFILES BY SESSION COUNT View the most active Access profiles by number of sessions over time.
Name Displays name of the Access profile.
Session Count Displays the number of sessions for each Access profile over time.

Using BIG-IQ, you may generate reports on session data for both user-defined and system-generated access control lists (ACLs). ACLs restrict user access to host and port combinations that are specified in access control entries (ACEs). You can create ACLs when configuring an Access Group, and BIG-IQ will also generate them automatically whenever you create a portal access resource, an app tunnel, or a a remote desktop configuration.

Generate reports on ACL usage by action count. You can also use BIG-IQ to view the session details associated with a particular ACL result, and view all log messages for both allowed and denied ACL results.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to generate a chart to summarize the top Access Control Lists (ACLs) and a table with data for the top ACLs by action count.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > ACL > ACL Usage.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. Use the ACL Action Type dropdown to view results for one type of action.

    • Allow: Permit the traffic.
    • Continue: Skip checking against the remaining access control entries in this ACL and continue evaluation at the next ACL.
    • Discard: Drop the packet silently.
    • Reject: Drop the packet and send a TCP RST message on TCP flows or proper ICMP messages on UDP flows. Silently drop the packet on other protocols.
  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. For the Top 5 ACLs chart, select the name of an ACL in order to remove it or add it to the chart view.

BIG-IQ Access allows you to record and view Access Control List (ACL) usage data for an Access group or for a single managed BIG-IP device. See the notes below to learn more about the categories for which you can data.

Vale or Chart title Functionality
TOP 5 ACLS View the number of ACLs over time for each access profile. This chart will display data for a maximum of 5 ACLs.
Name Displays name of the ACL.
Action Count Displays the number of actions for each ACLs over time.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to create a summary report of sessions by Access Control List (ACL) result, and see specific information for each session in the report.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > ACL > ACL Summary.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. Select one of the options from the ACL Results dropdown menu to display sessions with a specific ACL result. By default, sessions with all ACL results display. You can show allowed results only or denied results only by showing the ACL RESULTS dropdown menu. Select All ACL Results to generate a report for sessions with all ACL results.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. Click the blue session ID to open the Session Details screen, displaying session details and session variables.

  8. Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.

  9. Select Close.

BIG-IQ Access allows you to record Access Control List (ACL) summary data for an Access group or for a single managed BIG-IP device. See the notes below to learn more about each category for which you can record data.

Property Functionality
Local Time Displays the date and time that the ACL was created.
HostName Displays the BIG-IP device name.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
ACL Result Displays ACL result: Allow, Continue, or Reject.
Src IP Displays the source IP address.
Src Port Displays the source port number.
Dest IP Displays the destination IP address.
Dest Port Displays the destination port number.
Virtual IP Displays the IP address of the virtual server where the ACL originated.
Scheme Displays the authorization scheme that corresponds to the ACL.
Host Displays the host network that corresponds to the ACL.
Path Displays the path to which the ACL belongs.
Partition Displays the partition to which the ACL belongs. Only roles that are granted access to a partition can view the objects (such as the ACL) that the partition contains. If the ACL resides in the Common partition, all roles can access it.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to generate a report for all ACL log messages. You can configure the report by ACL result and view session details.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > ACL > ACL Log Messages.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. Select one of the options from the ACL Results dropdown menu to display sessions with a specific ACL result. By default, sessions with all ACL results display. You can show allowed results only or denied results only by showing the ACL RESULTS dropdown menu. Select All ACL Results to generate a report for sessions with all ACL results.

  5. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  6. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  7. Click the blue session ID to open the Session Details screen, displaying session details and session variables.

  8. Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.

  9. Select Close.

BIG-IQ Access allows you to record log messages for Access Control Lists (ACLs). See the notes below to learn more about each category for which you can record data.

Properties Functionality
Local Time Displays the time and date the error message occurred.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
HostName Displays the managed BIG-IP device name.
ACL Result Displays the ACL result.
ACL Name Displays the name of the ACL.
Log Message Displays the log message.

You can monitor session data for session requests initiated by an IP address listed in the IP intelligence database. The IP intelligence database contains only IP addresses that are considered untrustworthy, as a result of having performed exploits or attacks. Learn more about the F5 IP intelligence database here: https://support.f5.com/csp/article/K41310205.

To BIG-IQ to record data for this metric, you will need to have configured an Access policy with an IP Reputation Lookup agent. This agent allows Access to search for the IP address in the IP intelligence database.

If a session is initiated from an IP with a bad reputation, this means that the IP address exists in the IP intelligence database and the session request will be blocked. For example, the IP address may be a spam source or an infected system. APM sets rules to identify IP reputation by default, based on category. If you discover any categories that are categorized as bad reputations that you find acceptable to initiate a session, you can update the iRule or create another iRule to allow the session. If the IP reputation is good, the IP address is not found in the IP intelligence database and the session request can go through.

Use Access to monitor all session requests initiated by IP addresses with a bad reputation. You can also use this workflow to determine the category of IP reputation and to view detailed session information.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Enable IP intelligence on you managed BIG-IP devices in order to populate the IP intelligence database.

Use BIG-IQ to view session data for IP addresses in the IP intelligence database.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Bad IP Reputation.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. From the IP REPUTATION RATIO (ALL SESSIONS) pie chart, select Bad to view session details for session requests originating from IP addresses in the IP intelligence database. You can view data such top client IPs, top countries which sessions are originating from, top users, top Access profiles, top virtual servers, and top Access policy results.

    You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you were interested in viewing details on sessions originating from IP addresses in the intelligence database and originating from the United States, you would select Bad from the IP REPUTATION RATIO (ALL SESSIONS) pie chart and then select the dot over the United States in the map under TOP 10 COUNTRIES.

  7. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

BIG-IQ Access allows you to monitor APM sessions that originate from IP addresses that are present in the IP intelligence database. See the notes below to learn more about each category for which you can record data for

Chart title Functionality
IP REPUTATION RATIO (ALL SESSIONS) View the IP reputation ratio as a ratio of bad to other for all sessions.
Local Time Displays the time and date.
HostName Displays the BIG-IP device name.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
Client IP Displays the IP address of the client device.
IP Reputation Displays the category of the IP reputation.

From the Access dashboards in BIG-IQ, you can view browser and operating system (OS) information, as well as detailed session information, for specific managed BIG-IP devices provisioned for Access usage or for all devices in an Access group. Use BIG-IQ to monitor data on which browsers and operating systems are being used to initiate session requests, and to view detailed session data per operating system.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

You can use BIG-IQ to view session data organized by browser and operating system information for a particular managed BIG-IP device or for all devices in an Access group.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Browser and OS.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. To learn which browsers are most commonly being used to initiate sessions, view the data under the BROWSER VERSIONS BY SESSION COUNT chart.

  7. In the OS PLATFORM VERSIONS BY SESSION COUNT chart, select one of the segments of the pie chart bars to view session details for that OS. Available session details include top client IPs using that OS, top countries initiating sessions from that OS, top users, top Access profiles, top virtual servers, top Access policy results, and detailed session information.

    Note: You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about sessions originating from Windows 8 and using the same virtual server, you would select Win8 from the OS PLATFORM VERSIONS BY SESSION COUNT dashboard and then select the horizontal bar by the virtual server you are interested in under TOP 10 VIRTUAL SERVERS.

  8. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

BIG-IQ Access allows you to view session data, organized by browser and operating system details, for a particular Access device or for all devices in an Access group. See the notes below to learn more about each category for which you can record data.

Chart title or property Functionality
BROWSER VERSIONS BY SESSION COUNT View the browser versions by session count.
OS PLATFORM VERSIONS BY SESSION COUNT View the OS platform versions by session count.
Browser/Application Displays the browser or application type.
Version Displays the browser or application version.
OS Displays the operating system type.
Count Displays the session count.

Use BIG-IQ Centralized Management to view the distribution of sessions organized by geographic location. From this report, you can view a map representing the geographic origin of all sessions initiated within a specified time period, and obtain detailed information for each session represented in the report.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to generate a report to view the distribution of sessions organized by geographic location.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > By Geolocation.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. To view session data by country, go to the map titled SESSION COUNT DISTRIBUTION ACROSS COUNTRIES. Use your cursor to move the view to the part of the map you are interested in, or use + and - to zoom in or zoom out.

  7. To view session data for one country, click the colored dot on the country you are interested in.

    A dashboard with data on the top client IP addresses, top users, top Access profiles, top virtual servers, top client platforms, and most common Access policy results will display.

    Note: You can continue to drill down based on the information you are interested in. For example, if you were interested in session requests originating from the United States using the ca_policy an Access profile you have created for California residents, you would select the United States from the SESSION COUNT DISTRIBUTION ACROSS COUNTRIES, and then when the next dashboard loads, you would select your Access profile named /Common/ca_policy from under TOP 10 ACCESS PROFILES.

  8. To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.

  9. To view session data originating from a particular state or province, perform the same steps as above with the SESSION COUNT DISTRIBUTION ACROSS STATES chart.

BIG-IQ Access allows you view the distribution of all APM sessions by geographic location. See the notes below to learn more about each category you can record data for.

Chart title Functionality
SESSION COUNT DISTRIBUTION ACROSS COUNTRIES View the session count distribution across countries.
SESSION COUNT DISTRIBUTION ACROSS STATES View the session count distribution across states or provinces.
State/Province Displays the state or province where the sessions originated.
Country Displays the country where the sessions originated.
Continent Displays the continent where the sessions originated.
Count Displays the session count.

You can monitor the sessions that BIG-IQ® Centralized Management denies. By using the Access Monitoring option, you can view the following information:

  • The history of denied sessions
  • The reasons why sessions were denied
  • The top denied users, sorted by session count
  • The top authentication failures
  • The top denied policies
  • The top denied sessions by country of origin
  • The top denied session by the virtual server
  • The denied sessions, sorted by the client platform

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to generate a report on which sessions were denied by your Access policies, as well to create a report.

  1. Click Monitoring > DASHBOARDS > Access > Sessions > Denied.

  2. From the ACCESS GROUP/DEVICE list at upper left, select Managed Devices, or one or more of these options:

    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. From the DENIED SESSIONS/AUTH FAILURES OVER TIME chart, select or deselect Auth Failures or Denied Sessions from the top right corner of the chart to add or remove them from view.

  6. From any of the bar charts, select one of the horizontal bars to view details such as the authentication failure categories, top 10 reasons for denied sessions, top 10 denied users, top 10 denied Access policies, top 10 virtual servers by denied sessions, and top 10 client platforms by denied sessions.

    You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about LDAP failures associated with a particular Access policy, click the bar by the Access policy you are interested in under the chart TOP 10 DENIED POLICIES, then on the next screen, select the bar by LDAP Failure under the TOP 10 DENIED REASONS chart. The customized dashboard will display all LDAP failures that resulted in denied sessions and originated from a single Access policy.

  7. To exit out of the nested view or to move up one level, select the blue links at the top with the dashboard you would like to navigate to.

From here, you can view details regarding denied sessions and create a report.

BIG-IQ Access allows you to monitor denied Access Control List (ACL) sessions data. See the notes below to learn more about each category for which you can record data.

Chart title or property Functionality
Denied Sessions/Auth Failures Over Time View denied sessions and authentication failures over time.
Top 10 Auth Failures Categories Displays the 10 most common session authentication failures during the specified time period.
Top 10 Denied Reasons Displays the 10 most common reasons the session request was denied for the specified time period.
Top 10 Denied Users Displays the top 10 users who most frequently experienced a denied session request.
Top 10 Denied Policies Displays the top 10 Access policies involved in denied session requests over the specified time period.
Top 10 Virtual Servers by Denied Sessions Displays the top 10 virtual servers involved in denied session requests over the specified time period.
Top 10 Client Platform by Denied Sessions Displays the top 10 client platforms used to initiate a denied session request.
Local Time Displays the date and time that the ACL was created.
HostName Displays the BIG-IP device name.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
User Name Displays the user name for the BIG-IP device.
Denied Reason Displays the reason the session was denied.
Auth Failure Displays authentication failure category.
Virtual IP Displays the IP address of the virtual server.
Client IP Displays the IP address of the client.
Client OS Displays the operating system of the client.
Access Profile Displays the Access profile associated with the ACL session.
Country Displays country where the session originated.

Endpoint (client-side) security is a strategy for ensuring that a client device does not present a security risk before it is granted a remote-access connection to the network. Endpoint software verifies that desktop antivirus and firewall software is in place, systems are patched, keyloggers or other dangerous processes are not running, and sensitive data is not left behind in web caches and other vulnerable locations.

Use BIG-IQ Centralized Management to record and view data for the various endpoint security products used by APM users who initiate session requests. You can also view session details for each session where endpoint checks were performed.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to record data for sessions involving endpoint security check software.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Endpoint Software > Endpoint Software Summary.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. In the SOFTWARE CHECKS TYPE chart, select one of the horizontal bars to view details such as the users, endpoint check products, geolocation distribution, and client OS involved in this endpoint check.

    You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about antivirus checks initiated by the user Julie, you would select Antivirus from the SOFTWARE CHECKS TYPE dashboard and then select the horizontal bar by Julie’s name under the chart TOP 10 Users.

  7. To exit out of the nested view or to move up one level, select the blue links at the top with the dashboard you would like to navigate to.

  8. In the TOP 10 USED PRODUCTS chart, select a software check product that you would like to view details for. You may view details such as top users, vendor information, geolocation data, and client OS distribution, as well as session data.

    You can continue drilling down in this dashboard to customize the view depending on what information you are interested in.

    Exit out of the nested view when you are finished.

  9. In the TOP 10 VENDORS USED chart, select a software check vendor that you would like to view details for. You may view details such as top users, software check product information, geolocation data, and client OS distribution, as well as session data.

    You can continue drilling down in this dashboard to customize the view depending on what information you are interested in.

    Exit out of the nested view when you are finished.

BIG-IQ Access allows you to monitor endpoint security check summary data for each established session. See the notes below to learn more about each category for which you can record data.

Chart title or property Functionality
SOFTWARE CHECKS TYPES Displays the types of software checks.
TOP 10 USED PRODUCTS Displays the top ten products used.
TOP 10 USED VENDORS Displays the top ten vendors used.
Top 100 Products, Vendors Types by used count Displays the top 100 products and the type of vendors used.
Type Displays the type of vendor used for the software check.
Product Name Displays the name of the product used for the endpoint software check.
Vendor Name Displays the name of the vendor who provides the product for the software check.
Version Displays the software version for the product providing the software check.
Usage Count Displays the number of times the product was used for an endpoint software check.
Distinct Users Displays the number of individual users who initiated the endpoint software check.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to generate detailed reports for sessions involving endpoint security checks.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > Endpoint Software > Endpoint Software Details.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. Choose to view logs of only one severity by selecting a value from the Log Level dropdown.

  7. Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.

  8. Select Close.

BIG-IQ Access allows you to monitor endpoint security check details for each established session. See the notes below to learn more about each category for which you can record data.

Property Functionality
Local Time Displays the local timestamp when the endpoint check took place.
Hostname Displays the BIG-IQ system from which the endpoint check originates.
Cluster Displays the BIG-IQ cluster.
Session ID Click the session ID to open the Session Details screen, displaying session details and session variables.
Product Name Displays the name of the product with endpoint software.
Vendor Name Displays name of the vendor who supplies the product.
Version Displays the product version.
User Name Displays the logon name used to perform the endpoint check.
Client OS Displays the operating system where the endpoint check originates.
Continent Displays the continent where the endpoint check originates.
Country Displays the country where the endpoint check originates.
State Displays the state or province where the endpoint check originates.

Use BIG-IQ Centralized Management to monitor APM license usage to monitor if you are close to your license usage limits for BIG-IQ APM. You can monitor the number of users with active Access sessions, Connectivity sessions, and Secure Web Gateway (SWG) sessions.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

Use BIG-IQ to monitor the number of sessions by license usage, including Access sessions, Connectivity sessions, and SWG sessions.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > License Usage.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. Select up to 5 managed BIG-IP devices from the hostname list in order to monitor the license usage originating from those devices.

  7. To add or remove a managed BIG-IP device from any of the license usage charts, select the hostname in the top right corner of the chart.

BIG-IQ Access allows you to monitor APM session data filtered by license usage: APM usage, Connectivity usage, and Secure Web Gateway usage. From this page, you can generate customizable and dynamic reports to monitor license usage by managed BIG-IP device. See the notes below to learn more about each category for which you can generate data.

Chart Title or Property Functionality
ACCESS SESSIONS Displays the number of APM sessions per day by device.
CONNECTIVITY SESSIONS Displays the number of Connectivity sessions per day by device.
SWG SESSIONS Displays the number of Secure Web Gateway (SWG) sessions per day by device.

From BIG-IQ, you can monitor the number of new APM sessions over a specified period of time in order to measure recent traffic or to troubleshoot recent session issues. Use the new sessions dashboard to view the total number of established sessions, timed-out session requests, and denied session requests.

Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:

  • Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
  • Discover and import the managed BIG-IP device
  • Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device

To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:

  • Admin
  • Access Manager
  • Access Deployer

You can use BIG-IQ to generate reports on new sessions.

  1. Navigate to Monitoring > DASHBOARDS > Access > Sessions > New Sessions.

  2. At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).

    • All Managed Devices Includes all Access devices that are currently discovered.
    • <Access group name> Select to include all devices in the Access group.
    • <Cluster display name> Select to include the devices in the cluster.
    • <Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
  3. From the TIMEFRAME menu, specify a time frame:

    • Select a predefined time period. These range from Last hour to Last 3 months.
    • Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
  4. To save report data in a comma-separated values (CSV) file, click the CSV Report button.

    The CSV file downloads.

  5. To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.

  6. Customize the NEW SESSIONS OVER TIME chart by selecting the session result you would like to view.

    For example, if you would like to filter your view by new session requests that were unsuccessful, select Denied and Timed Out from the top right corner of the chart.

BIG-IQ Access allows you to monitor new session data filtered by result of the session request. See the notes below to learn more about each category for which you can generate data.

Chart title or properties Functionality
NEW SESSIONS OVER TIME Displays the number of new sessions per day over a specified time period, organized by total sessions, established sessions, denied sessions, and timed out session requests.
Local Time Displays the time and date of the new ACL session.
Established / min Displays the number of sessions established per minute.
Denied / min Displays the number of sessions denied per minute.
Time out / min Displays the number of session timeouts per minute.
Total / min Displays the total number of sessions per minute.

You configure alert rules to define the thresholds that establish when an alert is a warning and when it is critical. BIG-IQ sends you APM email alerts to notify you when these error and license usage metrics meet the thresholds you specify.

  1. Click Applications > ALERT MANAGEMENT > Alert Rules.

    BIG-IQ displays the list of alert rules configured on this system.

  2. To create a new Alert Rule for an Access Group or a single BIG-IP device, select Add.

    You can also edit the default APM alert rules by clicking on default-access-health. Doing this will change the alerts for all devices managed by this BIG-IQ.

  3. Add a unique name and a description for this alert rule.

  4. Select Device access-health to configure this alert rule for APM.

  5. Select the check box by each of the metrics for which you would like to receive monitoring alerts.

    The metrics you can receive alerts for include: Network Access Reconnects, Network Access Errors, Bad IP Reputations, Denied Sessions, SAML - IdP Errors, SAML - SP Errors, Access Usage, Connectivity Usage, and SWG Usage.

  6. For each metric you decide to receive alerts for, set a number of occurrences at which you would like to receive a warning alert and a number of occurrences at which you would like to receive a critical alert.

  7. Click SNMP Traps to enable alerts sent from remote SNMP-enabled devices.

  8. To send alerts to an email inbox, select the check box by Email. Enter the emails to receive the alerts in the box below separated by commas.

  9. Under Devices, select the group of devices for which you would like to configure alerts. You can select an Access Group at this point.

  10. Select the BIG-IP devices and use the arrows to move them between the boxes.

  11. When you have finished, click Save & Close.

When you finish, you will start receiving alerts (either in BIG-IQ, or your email, or both) based on what you configured.

Before you can use BIG-IQ to monitor APM alerts, you must first create alert rules that define the thresholds that establish when an alert is a warning and when it is critical.

You can use BIG-IQ to monitor both current APM alerts and past APM alerts to determine trends with network access and connectivity issues.

  1. Click Applications > ALERT MANAGEMENT > Active Alerts.

  2. You can sort all active alerts by alert Level, Title, Start time, Type, Context, Reported Object, and Last Updated.

    Sorting by Type can be particularly important when you are searching for alerts associated with the health of APM configurations.

  3. Once APM alerts are inactive, they will move to the Alert History tab under Applications > ALERT MANAGEMENT.

  4. From there, you can filter results by the last day and by the last two days from the dropdown menu in the top left in order to triage connection errors and other network issues for users of an APM connection.

You can use the BIG-IQ Centralized Management Access reporting tools to view the user dashboard for data on a specific user.

  1. Click Monitoring > DASHBOARDS > Access > User Summary.

    The User Summary screen displays, showing detailed information for specific users.

  2. Click on a User Name to display additional detail for that user.

You can monitor your user base by viewing the BIG-IQ Centralized Management Access user dashboard for data on specific users. The system displays which users created the most sessions, were denied the most sessions, and had the longest total session duration. You may use the user summary dashboard to view and monitor per-session and per-request data for all end-users accessing the network through an Access Policy, or for a specific user. Use this dashboard to troubleshoot connectivity and security issues for a specific user accessing the network.

Dashboard Functionality
TOP 10 USERS BY SESSION COUNT Displays the the top 10 most frequent users and the number of sessions per user. Click on a user to open a new screen that displays the user summary for that specific user.
TOP 10 USERS BY DENIED SESSION COUNT Displays the top 10 users who most frequently attempted to start a session but were denied by the BIG-IQ system.
TOP 10 USERS BY TOTAL SESSION DURATION Displays the top 10 users with the longest total session time for the selected timeframe.
Chart Functionality
Session Dashboard Displays session information, including the overall number or sessions, the number of denied sessions, and the overall session duration for the timeframe selected.
Client Information Dashboard Displays the number of unique devices that established a session, the number of unique geographical locations from where the devices logged in, and the number of unique application URLs.
Network Access Dashboard Displays network access information, including the total number of network access sessions, the total bytes transferred, and the overall session duration.
Federation Dashboard Displays the total number of SAML assertions and OAuth tokens.
SESSION COUNTS OVER TIME Displays the total number of sessions over time for the selected timeframe for this user, separated by Allowed and Denied sessions.
SESSION DURATION OVER TIME Displays the total duration of each session for this user over time for the selected timeframe, separated by Allowed and Denied sessions.
TOP 10 CLIENT IP’S Lists the 10 most common IP addresses the client used to access the network during the given timeframe. Select any one of these IPs to drill down and learn more information.
LOGON DEVICE DISTRIBUTION Lists the geographic distribution of each logon device.
SESSION TERMINATION REASONS Displays the most common reasons for session termination for this user. Select a termination reason to learn more about a type of termination, such as associated access policies, logon devices, and more.
IDENTITY FAILURES Displays the identity and Federation failures coming from Active Directory, LDAP, RADIUS, HTTP, SAML, and OIDC.
DEVICE POSTURE FAILURES Displays the failures associated with device posture checks, including but not limited to antivirus, firewall, and HW encryption. Select a failure to learn more about that failure type.
DENIED SESSION REASONS Lists the denied session reasons for this user and the number of denied sessions for each category. Select a reason to learn more about this type of denial.
DENIED RADIUS (MFA) FAILURES Displays the list of RADIUS multi-factor authentication failures for this user. Click on a failure to learn more.
TOP 10 ACCESS PROFILES Lists the top 10 access profiles for this user. Select an access profile to see more data associated with this user’s activity on this access profile.
TOP 10 VIRTUAL SERVERS Lists the top 10 virtual server IP addresses for this user and the number of times it has been used by this client during the selected timeframe. Select an IP address to learn more acount activity on a certain virtual server.
TOP 10 CLIENT PLATFORMS Displays the top 10 operating systems this user is accessing the network from. Click a platform to drill down and learn more about user activity on this operating system.
TOP 10 ACCESS POLICY RESULTS Lists the top 10 access polciies associated with this user’s network access. Select an access policy to learn more about this user’s activity associated with that policy or to determine which policy you may need to troubleshoot in the Configuration tab.
TOP 10 APPLICATIONS Lists the top 10 applications the user has accessed on the network.
TOP 10 ENDPOINT SOFTWARE PRODUCTS View the top 10 endpoint security products used by the client to access the network.
LOGON DISTRIBUTION BY LOCATION View the geographic distribution of user logons from this map. Use this map to determine if a user may have logged on from different geographic locations during a single session.
Kill User Sessions View the geographic distribution of user logons from this map. Use this map to determine if a user may have logged on from different geographic locations during a single session.