Access reports focus on session and logging data from Access devices (managed devices with APM licensed and provisioned). F5 Secure Web Gateway Services reports focus on user requests (for URLs or applications, for example) from Access devices with Secure Web Gateway Services provisioned. BIG-IQ Centralized Management Access also supports high availability. Thus, users can view both Access and SWG reports on a secondary BIG-IQ system.
Access reports and SWG reports provide the following features.
Reports on any combination of discovered devices, Access groups, and clusters
Graphs for typical areas of concern and interest, such as cross-geographical comparisons or top 10 issues
Tabular data to support the graphs
Granular user data
Ability in some screens to drill down from summarized data to details
The All Devices option for Access reports includes data from the devices that are currently managed (discovered) in the BIG-IQ system. This is in addition to data from devices that were managed at some point during the report timeframe, but that are not currently managed. With All Devices selected, if data from unmanaged devices exists, it displays in reports.
An unmanaged device might be unmanaged temporarily or permanently. Any time a configuration management change causes APM® to be undiscovered, the device and its data are moved to All Devices until APM is re-discovered on the device.
You cannot generate a report for an unmanaged device. However, you can generate a report for the timeframe when the device was managed, and then search the report for the unmanaged device name. In the Summary report, All Active Sessions includes the number of sessions that were active on the device when it became unmanaged. Those sessions stay in the Summary and in the Active sessions reports until the next session status update, which occurs every 15 minutes.
For Access Policy Manager (APM) to have monitoring data for your device, you must add the BIG-IP device to the BIG-IQ Centralized Management system. The system must then discover the device, and a user must run the Access remote logging configuration on the device. You can use the Access Summary dashboard to view aggregated data from APM policies managed by this BIG-IQ environment. Data you can view includes authentication, connectivity, user, session, and license information. To do so, on the Main tab, navigate to Monitoring > DASHBOARDS > Access > Access Summary.
Widget Title
Description
ACCESS GROUP/DEVICE
Select Managed Devices or select one or more of these options:
Select All Devices to view data from all BIG-IP devices managed by this BIG-IQ.
Select All Managed Devices to view data from all devices provisioned with APM managed by this BIG-IQ.
Select the name of an Access group name to include all devices in a specified Access group.
Select the name of a cluster to view the reported Access data from a cluster of BIG-IP devices.
Select the name of a BIG-IP device to view APM data from the device in this report.
TIMEFRAME
Adjust the time frame to reflect the period for which you would like to view data. You can do this by either: selecting the interval from the TIMEFRAME drop down menu, or by dragging the date selector from the horizontal widget below it.
Note: You can also select a timeframe between two specific dates or before or after a selected date by selecting Between,Before, or After and then selecting a date or date range from the calendar widget.
Once you have selected the time frame or date range you are interested in, the data on this dashboard will change to reflect the new time period.
All Active Users
From this dashlet, you can view all unique users with an active session using this device or devices. You can drill down on this information and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.
Sessions Created
From this widget, you can view all new sessions initiated during the timeframe currently displayed at the top of the page. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.
Unique Users
View the number of unique users during the timeframe specified at the top of the page. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.
Sign-In Denied
From this widget, you can view the number of sessions that have been denied. Select this widget to drill down and obtain more data about: top 10 client IP addresses, top 10 countries, top 10 users, top 10 Access profiles, top 10 virtual servers, top 10 client profiles, and top 10 Access policies associated with this metric.
Active Sessions Over Time
You can track the Average Established number of sessions in an interval of time, the Average Attempted number of sessions in one interval of time, the Maximum Established number of sessions in an interval of time, and the Maximum Attempted number of sessions in an interval of time. You can remove any of these components from the graph to focus your report by selecting the name of the component in the ledger at the top right corner of the chart.
The time intervals with the horizontal axis will adjust depending on the length of time you select in the Timeframe widget at the top of the page. For example, longer time frames will yield larger intervals for data collection and shorter time frames will yield shorter intervals for data collection. Average and Maximum refer to the aggregated data in a single unit of time on the horizontal axis. You can check what units of time the graph is using in the top left corner of the chart.
Denied Sessions / Auth Failures Over Time
This widget allows you to track denied sessions and Authentication failures against each other. You can remove either denies sessions or Authentication failures from the data set by selecting either of these components in the legend at the top right corner of the chart.
Top 3 Devices by License Usage
You can view devices by license usage in one of three categories: Access Sessions, Connectivity Sessions, and Secure Web Gateway (SWG) Sessions. Click on any of these categories to view the license usage for each, including the threshold and usage limit of each of the top three devices. By hovering over the bar graph for a device, you can view how many users are licensed for this device (displayed as the Limit) and how many are currently using it (displayed as Usage.
Session Count Distribution Across Countries
Use this widget to select a geographic location to view from the map to view more information about session logon locations in another dashboard. You can also view more data about sessions originating from unknown location by clicking on Unknown Locations at the bottom of the dashlet. To zoom in or out on the map widget, use the + and - icons.
Top Users by Session Count
You can view the top 10 users with the most sessions for this device or set of devices. To learn more about the activity of each user, select the name to navigate to a summary dashboard displaying usage data for this user only.
When you upgrade a BIG-IQ® Centralized Management system without taking a snapshot, it deletes all reporting data, including both Access and SWG reports. After upgrading, users cannot obtain these reports from the BIG-IP® devices. To prevent the loss of reports, users should take an Elasticsearch snapshot before upgrading, and restore the snapshot after upgrading. For more information on elastic snapshots, refer to F5 BIG-IQ Centralized Management: Upgrading Logging Nodes to Version x.x.
A session is over, but it continues to display in the Active sessions report.
Resolution
If a session starts when logging nodes are up and working, but terminates during a period when logging modes are unavailable, the session remains in the Active sessions report for 15 minutes. After 15 minutes, the session status is updated and the session is dropped from the report.
Problem
Active sessions are included in the Summary and Active sessions reports for a device that is no longer managed.
Resolution
Sessions were active on a device when it was removed from an Access group and became unmanaged. Sessions that were active when the device became unmanaged remain counted in All Active Sessions on the Summary screen and stay in the Active sessions report until the next session status update, which occurs every 15 minutes.
Problem
A session is over, but Session Termination and Session Duration are blank in a session report.
Resolution
If a session starts when logging nodes are up and working but terminates during a period when logging nodes are unavailable, the session termination is not recorded and the session duration cannot be calculated.
When you upgrade a BIG-IQ® Centralized Management system without taking a snapshot, it deletes all reporting data, including both Access and SWG reports. After upgrading, users cannot obtain these reports from the BIG-IP® devices. To prevent the loss of reports, users should take an Elasticsearch snapshot before upgrading, and restore the snapshot after upgrading. For more information on elastic snapshots, refer to F5 BIG-IQ Centralized Management: Upgrading Logging Nodes to Version x.x.
When you run an Access report or an SWG report, Access can get up to 10,000 records to display to you. After you scroll to the end of those 10,000 records, Access displays a message. At that point, all you can do is select fewer devices or select a shorter timeframe.
BIG-IQ Access users can configure managed BIG-IP devices in an Access Group to act as an OAuth authorization server or a resource server. Once you have configured an OAuth Authorization Server, you can use BIG-IQ to monitor the number of the tokens requested and generated by the OAuth Authorization Server, view the number of client applications used to access external resources, and view the number of errors the OAuth Authorization Server has encountered. You can also organize the Authorization Server Summary report by grant type or view data from a specific time period.
Use the Authorization Server Summary dashboard to troubleshoot issues with the BIG-IP device you have configured as an OAuth Authorization Server.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
You can use BIG-IQ Centralized Management to generate a summary report for your OAuth authorization server. Controls on this screen work together so you can fine-tune the statistics display. You may also use this workflow to revoke an OAuth token.
Navigate to Monitoring > DASHBOARDS > Access > Federation > OAuth > Authorization Server > Authorization Server Summary.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To change the OAuth authorization server you view in this report, make a selection from the AUTHORIZATION SERVER list.
To change the OAuth grant type displayed on this screen, make a selection from the GRANT TYPE dropdown list. You can choose to generate a report for Resource Owner Password Credentials (ROPC) grant types, implicit grant types, or authorization code grant types.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Total Access Tokens, Token Errors, Unique Users, Unique Client Apps, or Introspection Errors. BIG-IQ displays a screen with additional metrics for this recorded category.
Note: For example, to view all token errors tha result from the authorization code request type, select Token Errors, then view the data you are interested in under the chart titled TOP ERRORS BY REQUEST TYPE.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
To add or remove metrics for token generation, on the TOKEN GENERATION REQUESTS OVER TIME chart, click on the name of the metric that you want to remove..
You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 USERS, TOP 10 CLIENT APPS, TOP 10 RESOURCE SERVERS, TOP 10 OAUTH CLIENT IP’S, GEOLOCATION DISTRIBUTION, and USER PLATFORM DISTRIBUTION.
Note: For example, to view data for a specific user and for a particular OAuth client IP address, select the user you are interested in under the TOP 10 USERS dashboard, and then select the IP address under the TOP 10 OAUTH CLIENT IP’s dashboard.
As you drill down, you will be able to view customized combinations of data.
To revoke an OAuth token, drill down one level into any of the fields on the dashboard. At the bottom of the screen, select the checkbox next to the OAuth tokens you wish to revoke.
Select Revoke Selected Tokens, and then select OK.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
Use the Authorization Server Summary dashboard to track the overall health of your OAuth server. See the notes below to learn more about each category for which you can record data.
BIG-IQ Access users can view the Authorization Server Performance screen to track the health of an OAuth authorization server. If you previously configured a managed BIG-IP device running APM as an OAuth Authorization Server, you will be able to track the health of the server from this dashboard. You can also troubleshoot issues with token generation requests, and view data for token generation organized by grant type. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
The Authentication Server Summary screen shows several charts that you can use to track the health of your authorization server role. Controls on this screen work together so you can fine-tune the statistics display.
Click Monitoring > DASHBOARDS > Access > Federation > OAuth > Authorization Server > Server Performance.
BIG-IQ opens the Authorization Server Performance screen.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
From the AUTHORIZATION SERVER list, select an OAuth authorization server.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To view data for a different OAuth resource, make a selection from the Resource dropdown.
For the line charts on this dashboard, select any of the metrics in order to remove or add each metric to the chart and view a customized data set.
The Authorization Server Performance screen shows several charts that you can use to track the health of your OAuth authorization server. See the notes below to learn more about each category for which you can record data.
If you have configured a managed BIG-IP device to function as an OAuth Authorization server, you can use BIG-IQ to track the health of your OAuth tokens and view key token metrics. To do so, view the Token Summary screen. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
The Token Summary screen shows several charts that you can use to track the health of your OAuth tokens. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
From the AUTHORIZATION SERVER list, select an OAuth authorization server.
From the GRANT TYPE list, select an OAuth grant type.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Total Access Tokens, Total Refresh Errors, Revoked Tokens, Expired Access Tokens, or Expired Refresh Tokens. BIG-IQ displays a screen with additional metrics for the selected category.
Note: For example, if you are interested in viewing all expired access tokens resulting clients using Windows, select Expired Access Tokens then view the data for Windows under the chart titled PLATFORM DISTRIBUTION.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
To filter the list of tokens, select an option from the TOKEN FILTER dropdown menu. Select one of the following: Access Tokens Issued, Access Tokens Expired, Refresh Tokens Issued, or Refresh Tokens Expired.
To revoke an OAuth token, use the list of OAuth tokens on the main Token Summary dashboard or drill down one level into any of the fields on the dashboard. At the bottom of the screen, select the checkbox next to the OAuth tokens you wish to revoke.
Select Revoke Selected Tokens, and then select OK.
The Token Summary screen shows several charts that you can use to track the health of your OAuth authorization server tokens. See the notes below to learn more about each category for which you can record data.
BIG-IQ Access users can configure a managed BIG-IP device to function as an OAuth client and resource server. With this configuration, customers can log on to using external OAuth accounts to gain access to the resources protected by the BIG-IP device provisioned with APM.
Once you have configured a BIG-IP device to act as an OAuth client, you can use BIG-IQ to monitor the health of the OAuth client. The Client Summary screen shows several charts that you can use to track the status of your OAuth client. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
From the Client Errors screen, you can view a full log of errors in the OAuth client configuration in order to troubleshoot issues with your OAuth client.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
You can use BIG-IQ to generate OAuth Client summary data. The Client Summary report shows several charts that you can use to track the health of your OAuth client. Controls on this screen work together so you can fine-tune the statistics display.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To view data for a different OAuth client, make a selection from the CLIENT dropdown list.
To view data for a different grant type, make a selection from the GRANT TYPE dropdown list.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Token Requests, Token Errors, Unique Users, or Connectivity Errors. BIG-IQ displays a screen with additional metrics for the select this recorded category.
Note: For example, to if you are interested in viewing all token requests initiated by a particular user, select Token Requests, and then view the data for the user you are interested in under the chart titled TOP 10 USERS. You can continue drilling down to further customize what displays on this screen.
To view details for a specific session, click the ID under the Session ID column.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
Under the OAUTH CLIENT PERFORMANCE OVER TIME line chart, select any of the metrics in order to remove or add each metric for token generation.
You can use the bar charts to drill down and generate a customized report. These dashboards are TOP 10 USERS, TOP 10 CLIENT IPs, TOP CLIENT PLATFORMS, and GEOLOCATION DISTRIBUTION.
Note: For example, if you wanted to view data for a specific user with requests originating from California, select the user you are interested in from under the TOP 10 USERS dashboard and then select California under the GEOLOCATION DISTRIBUTION dashboard.
You can continue drilling down further to view customized combinations of data.
In the second level of the dashboards, you can view a list of sessions associated with OAuth client usage.
To view details for a specific session, click the ID under the Session ID column.
The Client Summary screen shows several charts that you can use to track the health of your OAuth client. Each chart displays a different category of collected data.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
Use BIG-IQ Centralized Management to monitor OAuth client error logs. The Client Errors report shows a log of errors in the OAuth client configuration.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
View the list of error messages in the report. To view specific session details for one of the errors, click the ID under the Session ID column.
The Client Errors screen shows a list of errors in the OAuth client configuration. See the notes below to learn more about each field for which you can record data.
This field displays the time and date the error message occurred.
HostName
This field displays the hostname of the managed BIG-IP device that sent this error message.
Session ID
Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level
This field displays the log level of the error message.
BIG-IQ Access users can configure a managed BIG-IP device to act as an OAuth client and resource server. Once you have done so, you can view the OAuth Resource Summary screen to track the health of your OAuth resource. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only BIG-IQ users managing BIG-IP devices with OAuth provisioned can provide data for OAuth reports.
Use BIG-IQ Centralized Management to generate a summary report for your OAuth resource. The Resource Summary dashboard shows several charts that you can use to track the health of your OAuth resource. Controls on this screen work together so you can fine-tune the statistics display.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To view data for a different OAuth resource, make a selection from the Resource dropdown.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Token Validation Successes, Token Validation Errors, Unique Client IPs, or Connectivity Errors. BIG-IQ displays a screen with additional metrics for the selected category.
Note: For example, to see resource usage originating from a specific client IP address, select Unique Client IPs, then view the data for the IP address you are interested in under the chart titled TOP 10 CLIENT IPs. You can continue drilling down to view even more customized reports.
To view details for a specific session, click the ID under the Session ID column.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
Under the RESOURCE SERVER PERFORMANCE OVER TIME line chart, select any of the metrics in order to remove or add each metric to the chart for resource server performance.
You can use the bar charts to drill down and generate a customized dashboard. These charts are TOP 10 CLIENT IPs, TOP CLIENT PLATFORMS, and GEOLOCATION DISTRIBUTION.
Note: For example, to view data for a specific client IP address with requests originating from Seattle:
On the TOP 10 CLIENT IPs chart, select the IP address you are interested in.
On the map in the GEOLOCATION DISTRIBUTION chart, select Seattle.
Once you drill down, you will be able to view customized combinations of data for the selected Seattle IP address.
The Resource Summary screen shows several charts that you can use to track the health of your OAuth resource. Each chart displays a different category of collected data.
BIG-IQ Access users can configure a managed BIG-IP device with APM provisioned to act as a SAML service provider (SP). Once you have done so, use the SAML SP Summary dashboard to track the health of your SAML SP resource. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a managed BIG-IP device with SAML provisioned can provide data for SAML reports.
Use BIG-IQ Centralized Management to generate a summary report for SAML Service Provider (SP) resources. The SP Summary report shows several charts that you can use to track the health of your SAML SP resource. Controls on this screen work together so you can fine-tune the statistics display.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To view data for a different SAML service provider, make a selection from the SP dropdown list.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Assertions Success and Assertions Failed. A screen appears with additional metrics for this recorded category.
Note: For example, if you are interested in viewing all successful assertions from a particular OAuth service provider, select Successful Assertions. Then select a service provider under the chart titled TOP 10 SPs WITH SUCCESSFUL ASSERTIONS. Continue drilling down for a more specific report.
To view details for a specific session, click the ID under the Session ID column.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
Under the IDP ASSERTIONS OVER TIME line chart, select any of the metrics in order to remove or add each metric for the IdP assertion chart.
You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 IDPs WITH SUCCESSFUL ASSERTIONS, TOP 10 CLIENT IPs, TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS, and TOP 10 IDPs WITH FAILED ASSERTIONS.
Note: For example, if you wanted to view data for a specific user and for a particular OAuth client IP address, select the user you are interested in from under the TOP 10 USERS dashboard and then select the IP address under the TOP 10 OAUTH CLIENT IPs dashboard.
As you drill down, you will be able to view customized combinations of data.
The SP Summary screen shows several charts that you can use to track the health of your SAML SP resource. Each chart displays a different category of collected data.
BIG-IQ Access users can monitor SAML Service Provider assertion data using the SP Assertions dashboard. The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a BIG-IP device with SAML provisioned on it can provide data for SAML reports.
The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. Controls on this screen work together so you can fine-tune the statistics display.
The SP Assertions screen opens, displaying a table with assertion information.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To view data for a specific SAML service provider, select one from the SP dropdown list.
View the list of SP assertions in the table.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To view details for a specific session, click the ID under the Session ID column.
The SP Assertions screen shows several charts that you can use to track the health of your SAML SP assertions. See the notes below to learn more about each field for which you can record data.
Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Assertion Time
This field displays the time and date when the SP assertion occurred.
Name
This field displays the SP service.
User Name
This field displays the username attempting to sign on with Single Sign-ON (SSO).
HostName
This field displays managed BIG-IP device hostname.
Platform
This field displays the operating system of the client’s machine.
Cluster
This field displays the cluster attached to the SP service.
BIG-IQ Access users can generate SAML SP error reports to view a full length log for all error messages originating from a managed BIG-IP device serving as a SAML SP. To do so, use the SAML SP Error Report screen in BIG-IQ. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a BIG-IP device with SAML provisioned on it can provide data for SAML reports.
The SP Errors screen shows several charts that you can use to track the health of your SAML SP errors. Controls on this screen work together so you can fine-tune the statistics display.
The SP Error Reports screen opens, displaying the error logs.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To view data for a specific SAML service provider, select one from the SP dropdown list.
View the list of service provider errors in the table on the dashboard.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
View the list of service provider errors in the table on the dashboard.
To view details for a specific session, click the ID under the Session ID column.
The SP Errors screen shows several charts that you can use to track the health of your SAML SP errors. See the notes below to learn more about each field for which you can record data.
This field displays the time and date the error message occurred.
HostName
This field displays the hostname of the managed BIG-IP device from which this error message originated.
Session ID
Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level
This field displays the log level of the error message.
BIG-IQ Access users can configure managed BIG-IP devices with APM provisioned to act as a SAML Identity Provider (IdP) for Software as a Service (SaaS) applications. Configure managed BIG-IP devices as a SAML IdP to enable Single-Sign On to common applications. Once you have configured a BIG-IP device as an IdP, use BIG-IQ to track the health of your SAML IdP resource. Using the IdP Summary dashboard, you can view a variety of metrics to monitor SAML assertions and IdP errors.
Data appears on this dashboard when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a managed BIG-IP device with SAML provisioned can provide data for SAML reports.
Use BIG-IQ Centralized Management to generate a SAML Identity Provider report. The IdP Summary report shows several charts that you can use to track the health of your SAML IdP resource.
The IdP Summary screen opens, displaying a dashboard with summary information.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn more details for the categories across the top of the page, select Assertions Success and Assertions Failed. A screen appears with additional metrics for this recorded category.
Note: For example, if you are interested in viewing all successful assertions from a particular OAuth identity provider, select Successful Assertions. Then select an identity provider under the chart titled TOP 10 IDPs WITH SUCCESSFUL ASSERTIONS. Continue drilling down for a more customized report.
To view details for a specific session, click the ID under the Session ID column.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
Under the IDP ASSERTIONS OVER TIME line chart, select any of the metrics in order to remove or add each metric for the IdP assertion chart.
You can use the bar charts to drill down and generate a customized report. These charts are TOP 10 SPs WITH SUCCESSFUL ASSERTIONS, TOP 10 USERS, TOP 10 SUBJECT VALUES WITH SUCCESSFUL ASSERTIONS, and TOP 10 SPs WITH FAILED ASSERTIONS.
Note: For example, if you wanted to view data for a specific user and for a particular client IP address, select the user you are interested in from under the TOP 10 USERS dashboard and then select the IP address under the TOP 10 CLIENT IP’s dashboard.
As you drill down, you will be able to view customized combinations of data.
The IdP Summary screen shows several charts that you can use to track the health of your SAML IdP resource. Each chart displays a different category of collected data.
BIG-IQ Access users can monitor SAML Identity Provider assertion data using the IdP Assertions dashboard. The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdP assertions. Data appears when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a managed BIG-IP device with SAML provisioned on it can provide data for SAML reports.
The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdP assertions. Controls on this screen work together so you can fine-tune the statistics display.
The IdP Assertions screen opens, displaying a table with assertion information.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
View a list of IdP assertions in the dashboard for the selected SAML identity provider.
To view details for a specific session, click the ID under the Session ID column.
The IdP Assertions screen shows several charts that you can use to track the health of your SAML IdPs assertions. See the notes below to learn more about each field for which you can record data.
Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Assertion Time
This field displays the time and date when the SP assertion occurred.
Name
This field displays the name of the IdP service.
User Name
This field displays the username of the person using the managed BIG-IP device.
HostName
This field displays managed BIG-IP device hostname.
Platform
This field displays the operating system of the client’s machine.
Cluster
This field displays the cluster attached to the IdP service.
BIG-IQ Access users can generate SAML IdP error reports to view a full length log for all error messages originating from a managed BIG-IP device serving as a SAML IdP. To do so, use the SAML IdP Error Report screen in BIG-IQ. Data appears on the dashboard when you configure statistics collection. Controls on this screen work together so you can fine-tune the statistics display.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a managed BIG-IP device with SAML provisioned on it can provide data for SAML reports.
The IdP Errors screen shows several charts that you can use to track the health of your SAML IdP errors. Controls on this screen work together so you can fine-tune the statistics display.
The IdP Errors screen opens, displaying a table with reported errors.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
From the IdP dropdown menu, select one SAML identity provider to view a report for that resource.
View a list of IdP errors in this dashboard.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To view details for a specific session, click the ID under the Session ID column.
The IdP Errors screen shows several charts that you can use to track the health of your SAML IdP errors. Each chart displays a different category of collected data.
This field displays the time and date the error message occurred.
HostName
This field displays the hostname of the managed BIG-IP that generated this error message.
Session ID
Click the session ID to open the Session Details screen, displaying session details and session variables. From this screen, you can monitor log messages and customize your log message report by severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
Log Level
This field displays the log level of the error message.
Before you can display statistics in the SWG analytics screen, you must have the following configured:
A BIG-IQ data collection device configured for the BIG-IQ device
The BIG-IP device located in your network and running a compatible software version
To view the SWG Dashboard, statistics collection on the BIG-IP device should be enabled.
Note: For BIG-IP devices running versions 13.1.0.5 or later, enabling the BIG-IP device’s statistics collection may affect the information that appears in the Secure Web Gateway Summary screen (Monitoring > DASHBOARDS > Access > Secure Web Gateway > Secure Web Gateway Summary).
For BIG-IP devices running versions 13.1.0.5, or later, you must have AVR provisioned on your BIG-IP device.
View statistics for all traffic managed with Secure Web Gateway (SWG) to ensure that your configured access profile properly secures the users within your network.
Click Monitoring > DASHBOARDS > Access > SWG.
The screen displays the SWG analytics screen. By default, the screen displays statistics from the past hour. You can adjust the time settings using the controls found at the top of the screen.
To display events that correspond with the chart timeline, click Events.
Events that occurred within the selected time period are displayed in the chart. You can select the event icons within the chart to display event details.
Expand the dimensions found at the far right of the screen to view additional data.
Filter displayed data by dimension objects:
To filter data by one or more BIG-IP devices, expand BIG-IP Host Names or BIG-IP Blade Numbers and select one or more dimension objects.
To filter data by traffic or security settings (e.g. a URL category and a corresponding action) expand the remaining dimensions and select one or more dimension objects.
Note: You can select objects from multiple dimensions. Once you select an object, only dimensions with corresponding data are displayed in the charts and dimensions
Briefly explain the outcome of having completed this task. This element is optional, but recommended.
To edit your SWG settings go to Configuration > ACCESS > Access Groups and select the Access group name. For more information about Access group configuration, refer to the BIG-IQ Centralized Management: Access on support.f5.com for configuration information.
You can monitor your user base by viewing the BIG-IQ Centralized Management Access user dashboard for data on specific users. The system displays which users created the most sessions, were denied the most sessions, and had the longest total session duration. The administrator can enter a specific user name to get the following details for the user:
The user login locations on a world map
The total sessions, denied sessions, and session duration
The Access denied sessions.
The top authentication failures, including AD Auth and LDAP only
The device type users used to log into the system
The reason the system terminated the session
The login history showing the success and failures over time
The most accessed applications
The most accessed URLs
The login failure attempts over time, sorted by the reason
You can monitor your applications by viewing the BIG-IQ Centralized Management Access user dashboard for data on which applications are linked to the BIG-IQ Access component. The system displays the top applications used and the application usage time. Administrators can expand the GUI for a specific application and view the following information:
The application access history
The users who use the application the most
The access history
The world map, showing where the user is access the application
Logging nodes are highly available, but it is still possible for them to become unavailable. This could occur, for example, if all logging nodes are on devices in the same rack in a lab, and the power to the lab shuts down.
You can configure the BIG-IQ system to log information about BIG-IQ and Secure Web Gateway events and send the log messages to remote high-speed log servers.
When configuring remote high-speed logging of events, it is helpful to understand the objects you need to create and why, as described here:
Object
Reason
Pool of remote log servers
Create a pool of remote log servers to which the BIG-IP system can send log messages.
Destination (unformatted)
Create a log destination of Remote High-Speed Log type that specifies a pool of remote log servers.
Destination (formatted)
If your remote log servers are the ArcSight, Splunk, or Remote Syslog type, create an additional log destination to format the logs in the required format and forward the logs to a remote high-speed log destination.
Publisher
Create a log publisher to send logs to a set of specified log destinations.
Log Setting
Add event logging for the APM system and configure log levels for it or add logging for URL filter events, or both. Settings include the specification of up to two log publishers: one for access system logging and one for URL request logging.
Access profile
Add log settings to the access profile. The log settings for the access profile control logging for the traffic that comes through the virtual server to which the access profile is assigned.
Before creating a pool of log servers, gather the IP addresses of the servers that you want to include in the pool. Ensure that the remote log servers are configured to listen to and receive log messages from the BIG-IP system.
Create a pool of remote log servers to which the BIG-IP system can send log messages.
At the top of the screen, click Configuration.
On the Main tab, click Local Traffic > Pools.
The Pool List screen opens.
Click Create.
The New Pool screen opens.
In the Name field, type a unique name for the pool.
Using the New Members setting, add the IP address for each remote logging server that you want to include in the pool:
Type an IP address in the Address field, or select a node address from the Node List.
Type a service number in the Service Port field, or select a service name from the list.
Note: Typical remote logging servers require port 514.
Before you can create a new log destination, you must have configured a remote log server to send the logs to.
Use this screen to create a new log destination for a managed device.
Create a log destination to specify that log messages are sent to a remote log server.
At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Destinations.
The Log Destinations screen displays a list of the log destinations that are defined on this device.
To create a new log destination, click Create.
The New Log destination screen opens so you can define the settings you want for this destination.
In the Name field, type in a name for the log destination you are creating.
For Type, select the kind of destination you are creating.
Depending on the selection you make, additional controls are displayed.
Specify the additional settings needed to suit the requirements for this log destination. The fields required to create a new log destination depend on the type you choose. BIG-IQ denotes required fields using an amber box. You can also determine whether you have completed all of the required fields by noting whether the Save & Close button is enabled.
Note: Except for the Devices and Device Specific settings, the parameters on this screen perform the same function as they do when you configure a log destination on a BIG-IP device. For details about the purpose or function of a particular setting, refer to the BIG-IP reference information on support.f5.com. From the BIG-IP Knowledge Center, select the BIG-IP LTM module and the software version you have installed; then select the appropriate guide. For example, information about the log destination parameters for BIG-IP version 13.0 is provided in the External Monitoring of BIG-IP Systems: Implementations, Version 13.0 guide.
When you create a Log Destination and select a type of IPFIX or Remote High-Speed Log, you need to specify which devices to associate this destination with. When you create a Log Destination and select a type of Management Port you can specify device specific settings or, if no device specific settings are defined, the base configuration settings are used for any device associated with this log destination.
Note: For additional detail on device-specific log destination types, refer to What is a device specific log destination? in the F5 BIG-IQ Centralized Management: Local Traffic & Network Implementations guide on support.f5.com.
If you have a lot of devices that you need to associate with this log destination and want to automate the process:
Use the steps below to specify one device and then click Save.
Associate this log destination with the log publishers that are pinned to your managed devices.
Come back and edit this log destination. A Find Relevant Devices button displays. You can use this button to let BIG-IQ assemble a list of devices. BIG-IQ finds the BIG-IP devices that this destination can be deployed to. You can use the list to create a device-specific instance of this destination for each BIG-IP.
Click Save to add the listed devices to the Device Specific list.
To specify the devices for this log destination manually:
Select the device you want this destination to use
If you are creating an IPFIX or Remote High-Speed Log destination log, select the pool that you want each device to use.
Use the
button to add additional devices to the list.
Use the
button to remove a device from the list.
Click Save to add the listed devices to the Device Specific list.
Devices you select for this log destination are added to the Device Specific list.
Note: Click on a device name in the Device Specific list to edit settings for that device. Bear in mind though that changes you make to one device do not change the settings for other devices, or for the base configuration for the log destination.
Click Save & Close.
The system creates the new log destination with the settings you specified.
Changes that you make are made only to the pending version. The pending version serves as a repository for changes you stage before deploying them to the managed device. Object settings for the pending version are not the same as the object settings on the actual BIG-IP device until they are deployed or discarded.
When you finish specifying the settings for this log destination, the next step is to evaluate and then deploy the changes to the target device. Until you deploy the changes stored in the pending version, objects on the managed device are not changed.
Before you can create a new log publisher, configure a log destination with a pool of remote log servers so you can assign it to your publisher as you create it.
Log publishers specify log destinations that BIG-IP devices can send their log messages to.
At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Publishers.
The screen displays a list of the Log Publishers that are defined on this device.
To create a new log publisher, click Create.
The New Log Publisher screen opens so you can define the settings you want for this publisher.
In the Name field, type in a name for the log publisher you are creating.
Select the Log Destinations for this publisher.
Select a destination type from the Available list.
The list of destinations displays only the type you selected.
Select one or more destinations from the Available list.
Move the selected destinations to the Selected list.
If you are using a formatted destination, select the destination that matches your log servers, such as Remote Syslog, Splunk, or ArcSight.
Specify the additional settings needed to suit the requirements for this log publisher.
The parameters on this screen are optional and perform the same function as they do when you configure a log publisher on a BIG-IP device.
Note: For details about the purpose or function of a particular setting, refer to the BIG-IP reference information on support.f5.com. From the BIG-IP Knowledge Center, select the BIG-IP LTM module and the software version you have installed; then select the appropriate guide. For example, information about the log publisher parameters for BIG-IP version 13.0 is provided in the External Monitoring of BIG-IP Systems: Implementations guide.
Click Save & Close.
The system creates the new log publisher with the settings you specified.
Changes that you make are made only to the pending version. The pending version serves as a repository for changes you stage before deploying them to the managed device. Object settings for the pending version are not the same as the object settings on the actual BIG-IP device until they are deployed or discarded.
When you finish specifying the settings for this log publisher, the next step is to evaluate and then deploy the changes to the target device. Until you deploy the changes stored in the pending version, objects on the managed device are not changed.
Create log settings to enable event logging for access system events or URL filtering events or both. Log settings specify how to process event logs for the traffic that passes through a virtual server with a particular access profile.
At the top of the screen, select Configuration, then on the left side of the screen, click ACCESS > Access Groups.
Click the name of an Access group.
A new screen displays the group’s properties.
Click EVENT LOGS SETTINGS > Create.
Type a name for the name for the log setting.
In the SSO Configuration Description field, type a descriptive text for the configuration.
For Access System Logs, click the check box to specify a publisher for Access system logs and log levels.
For Access Logs Publisher, select a log publisher.
For the system log types, beginning with Access Policy and ending with ADFS Proxy, from the dropdown lists, select a log level. The default is Notice.
For URL Request Logs, click the check box to select a publisher for the logs and specifies the URL requests to log based on whether the request was blocked or allowed.
For URL Request Logs Publisher, select a log publisher.
For Log Allowed Events, click the check box to log request data when a user tries to access a URL that the URL filter allows.
For Log Blocked Events, click the check box to log request data when a user tries to access a URL that the URL filter blocks.
For Log Confirmed Events, click the check box to log request data when a user confirms a request for access to a URL for which the URL filter requires confirmation.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a device with SWG provisioned on it can provide data for Secure Web Gateway reports.
You can create SWG reports for Access groups, clusters (in Access groups), or devices that you select from the Access groups and clusters (in Access groups) on the BIG-IQ system.
At the top of the screen, click Monitoring.
Monitoring > DASHBOARDS > Access > Secure Web Gateway > Secure Web Gateway Summary.
A Summary report (for all devices and a default timeframe) starts to generate and display.
From the left, select any report that you want to run.
From the ACCESS GROUP/DEVICE list at upper left, select Managed Devices or select one or more of these options:
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Only a device with SWG provisioned on it can provide data for SWG reports.
From the Summary report, the initial display includes graphs that summarize the report data. You can get more detailed information by clicking a bar or a point on a graph to see additional graphs and tables with supporting entries.
At the top of the screen, click Monitoring.
On the left, select DASHBOARDS > Access > Secure Web Gateway.
The Summary starts to generate and display. A timeline and some summaries display across the top of the screen. Graphs display under the summaries. Each graph provide different views of the data.
Click any bar in a graph on the display to get more information.
Additional graphs provide different views of the data, and supporting data displays in a table at the bottom of the screen.
If more details are available, click the bars in the graphs to display them.
Scroll down to the table to view the supporting data.
BIG-IQ Centralized Management offers advanced monitoring and troubleshooting capabilities for connectivity and VPN use cases. You may use the remote access monitoring functionality to gain visibility into the behavior of VPN traffic, as well as to view the log of errors associated with failed connections. With remote access monitoring, you can maintain a high-level visibility for network access requests and session data for all users accessing the network through Access policies.
View data for Network Access usage summary. From this report, you can:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Displays the total number of users actively connected to a session. Click Active Users to open the Active Users screen, which displays charts describing the top 1,000 users and the top 1,000 locations.
Active Connections
Displays the total active connections. Click Active Connections to open the Active Connections screen, which displays charts describing the top 1,000 users and the top 1,000 locations.
Total Sessions
Displays the total number of sessions established.
Total Reconnects
Displays the number of times users tried to reestablish a session. Click Total Reconnects to open the Total Reconnects screen, which displays charts describing reconnects.
Network Access Session Errors
Displays the total number of errors that occurred during network access sessions. Click Network Access Session Errors to open the Connectivity Errors screen, which displays a list of connectivity errors. Click Session ID to display detailed session details and session variable information.
Displays a chart of the network access reconnects over time.
TOP 10 USERS BY RECONNECTS
Displays the top ten users with the most reconnects. Select a user from the bar chart to display detailed information about the user.
RECONNECTS GEO DISTRIBUTION
Displays the geographical locations from which the reconnects originate. Click the locations on the map to display detailed information about the country from which the reconnect originated.
CLIENTS IPS BY RECONNECTS
Displays the IP address of the client devices from which the reconnects originate. Select a client from the bar chart to display the types of client operating systems.
Each chart displays a title that identifies the statistic plotted on that chart.
NETWORK ACCESS SESSIONS OVER TIME
Displays the network access sessions over time.
TOP 10 USERS BY SESSIONS
Displays the users with the most sessions and the number of sessions per user. Select a user from the list to display detailed session information for that user.
TOP 10 USERS BY RECONNECTS
Displays the users with the most reconnects and the number of reconnects per user. Select a user from the list to display detailed reconnect information for that user.
SESSIONS GEO DISTRIBUTION
Displays the geographical locations from which the sessions originate. Click the locations on the map to display detailed information about the country from which the session originated.
TUNNEL TYPES BY SESSIONS
Displays the types of tunnels used by all sessions and the number of tunnels used. Click the ring chart to display detailed information about the tunnel types.
TOP 10 CLIENTS IPS BY SESSIONS
Displays the IP addresses of the top client systems from which the sessions originate and the number of sessions per client. Select a client from the bar chart to display detailed session information for that client.
CLIENT OS BY SESSIONS
Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.
Each chart displays a title that identifies the statistic plotted on that chart.
NETWORK ACCESS CONNECTIONS OVER TIME
Displays the network access connections over time.
TOP 10 USERS BY CONNECTIONS
Displays the users with the most connections and the number of connections per user. Select a user from the list to display detailed connections information for that user.
TOP 10 USERS BY RECONNECTS
Displays the users with the most reconnects and the number of reconnects per user. Select a user from the list to display detailed reconnect information for that user.
CONNECTIONS GEO DISTRIBUTION
Displays the geographical locations from which the connections originate. Click the locations on the map to display detailed information about the country from which the connection originated.
TUNNEL TYPES BY CONNECTIONS
Displays the types of tunnels used by all connections and the number of tunnels used. Click the pie chart to display detailed information about the tunnel types.
TOP 10 CLIENTS IPS BY CONNECTIONS
Displays the IP addresses of the top client systems from which the connections originate and the number of connections per client. Select a client from the bar chart to display detailed connection information for that client.
CLIENT OS BY CONNECTIONS
Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.
Each chart displays a title that identifies the statistic plotted on that chart.
NETWORK ACCESS BYTES TRANSFERRED OVER TIME
Displays the bytes transferred over time in the network access.
TOP 10 USERS BY BYTES TRANSFERRED
Displays the users with the most bytes transferred and the size of the transfers. Select a user from the list to display detailed information for that user.
BYTES TRANSFERRED GEO DISTRIBUTION
Displays the geographical locations from which the bytes originate. Click the locations on the map to display detailed information about the country from which the bytes originated.
TOP 10 CLIENTS IPS BY BYTES TRANSFERRED
Displays the IP addresses of the top client systems that transferred bytes of information and the size of the transfers. Select a client from the bar chart to display detailed bytes transferred information for that client.
CLIENT OS BY BYTES TRANSFERRED
Displays the top operating systems used by the client devices and the number of operating systems. Click the ring chart to display detailed information about the client device.
BIG-IQ Centralized Management allows you to monitor and troubleshoot network access requests by all clients attempting to join your network. You can use the aggregated data on the following page to understand the overall success of network access requests, and to view the amount of VPN traffic at any given moment or over a period of time.
To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Performance.
Within BIG-IQ, you can view data for Network Access performance. From this report, you may:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both.
Generate reports for any devices regardless of Access group membership, cluster membership, or geographic location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. You can adjust each end of the control. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
From BIQ-IQ, you may view a report of all of the reconnections to your network through your VPN. You may use this page to troubleshoot connectivity issues with your VPN or to determine if a connectivity issue lies on the client-side.
To do this, view a report for Network Access reconnections. Access this page at Monitoring > DASHBOARDS > Remote Access > Network Access > Network Access Recconnect Detail. From this page, you can:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Add or remove the Client Application field by clicking the settings icon on the right and selecting or deselecting Client Application report.
You may use BIG-IQ Centralized Management to log all error messages received for every failed network access request in order to facilitate troubleshooting efforts for an end-user or to understand trends with connectivity issues and come to a resolution. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Errors
View all details for Network Access errors. From this page, you can:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both.
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
BIG-IQ provides you with the ability to monitor the frequency of network access requests, as well as to drill-down on the data for all of these requests. You may request reports on traffic throughput for a specific user, and you may track the geographical location of all of the network access requests in order to prevent and spot session takeover or unauthorized network access. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Network Access > Network Access Usage.
From this page, you can:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
Displays the total number of network access connections.
Total Bytes In
Displays the total number of bytes received by the network access.
Total Bytes Out
Displays the total number of bytes sent out by the network access.
Total Bytes Transferred
Displays the total number of sent and received bytes.
Total Bytes Transferred
Displays the total number of sent and received bytes.
Total Duration
Displays the total duration when the network access connections for a user were active. When the user has multiple active connections at the same time, the total duration is the sum of the duration of those two connections.
Distinct Locations
Displays the number of unique locations from where the network access usage originates.
View network access usage for the top 1000 locations:
Country
Displays the countries from where the network access usage originates.
State
Displays the states in the countries from where the network access usage originates.
Total Connections
Displays the total number of network access connections.
Total Bytes In
Displays the total number of bytes received by the network access.
Total Bytes Out
Displays the total number of bytes sent out by the network access.
Total Bytes Transferred
Displays the total number of sent and received bytes.
Total Duration
Displays the total duration when the network access connections for a user were active. When the user has multiple active connections at the same time, the total duration is the sum of the duration of those two connections.
Note: The date filter is applied on the connection start time. If you select a date range that starts after the network access connection was established, BIG-IQ does not display the connection record because date range selected does not include connection state time.
BIG-IQ allows you to separately monitor portal access network traffic and network access requests that stem from BIG-IP Edge Client. To monitor data on portal access requests and to receive reports on this data, navigate to Monitoring > DASHBOARDS > Access > Remote Access > Portal Access.
View data for Portal Access sessions. From this report, you can:
Generate a report with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
View the number of client requests, cache hits, and cache misses over time in the Portal Access chart.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
You may use BIG-IQ to collect data on virtual desktop sessions in order to troubleshoot connectivity issues and view trends over time or for a certain time period. To do so, navigate to Monitoring > DASHBOARDS > Access > Remote Access > VDI Summary.
From this report, you can:
Generate reports with a different scope by making a selection from the ACCESS GROUP/DEVICE or the TIMEFRAME field, or both
Generate reports for any devices regardless of Access group membership, cluster membership, or geographical location. Select All Devices from the ACCESS GROUP/DEVICE list and select the devices that interest you.
View the number of client requests, cache hits, and cache misses over time in the Portal Access chart.
Adjust the time slider across the top of the screen to indicate the time window for which statistics are displayed. This control sets the chart pane focus to a specific window of time within the currently selected time period. Use the sliders at either end of this control to define the window you want to examine. If you adjust the right side of the control, the auto refresh stops, effectively freezing the display so you can focus on a particular data point.
Select CSV Report to download a CSV file of this data to your local machine.
Refresh this page by clicking Refresh or set up automatic refresh by selecting the arrow next to the Refresh button and selecting how often you would like to refresh the data. You can pick from 1, 5, or 10 minutes.
BIG-IQ Centralized Management allows users to monitor data for all session requests managed by Access Policy Manager (APM). Use BIG-IQ to create a summary report for all sessions, as well as to view individual session details and log messages.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
You can create session reports for any managed BIG-IP device with an APM configuration that has been discovered on the BIG-IQ system, whether or not the device is a member of an Access group. To create a report, you can select any combination of Access groups, clusters, and devices.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, and <Device name>).
All Devices Includes Access devices that are currently managed, and Access devices that were managed at one time but are not managed now. (A managed device is one that has been discovered with the APM service configuration.)
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> - Select to include all devices in the Access group.
<Cluster display name> - Select to include the devices in the cluster.
<Device name> - Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To view details for a specific session, click the ID under the Session ID column.
Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
BIG-IQ Access allows you to monitor APM session data from the Sessions Summary dashboard. From this page, you can generate customizable and dynamic reports to monitor top-level content for all sessions. See the notes below to learn more about each category for which you can record data.
Displays the date and time that the session was created.
Hostname
Displays the managed BIG-IP device name.
Cluster
Displays the High Availability (HA) cluster associated with the session.
Session ID
Click the Session ID to open the Session Details screen, displaying session details and session variables.
Session Duration
Displays the duration of time when the session was active.
Session Termination
Displays the local timestamp when the session was terminated.
Active
Displays a green dot if the session is active.
User Name
Displays the logon name used to start a session.
Virtual IP
Displays the IP address of the virtual server where the session started.
Client IP
Displays the IP address of the client that started the session.
Client OS
Displays the operating system of the client that started the session.
IP-Reputation
For a connection attempted from an IP address that exists in the IP reputation database on a device, specifies the category of IP reputation, or, Unknown when IP intelligence is not enabled on the BIG-IP device.
Continent
Displays the continent on which the client is located.
Country
Displays the country in which the client is located.
State
Displays the state or province in which the client is located.
BIG-IQ Access allows you to monitor APM session data for all active sessions. From this page, you can generate customizable and dynamic reports to monitor top-level content for all active sessions. See the notes below to learn more about each category for which you can generate data.
Displays the date and time that the session was created.
Hostname
Displays the managed BIG-IP device name.
Cluster
Displays the high availability cluster associated with the session.
Session ID
Click the session ID to open the Session Details screen, displaying session details and session variables.
User Name
Displays the logon name of the user who initiated this session.
Virtual IP
Displays the IP address of the virtual server where the session started..
Client IP
Displays the IP address of the client that started the session.
IP Reputation
For a connection attempted from an IP address that exists in the IP reputation database on a device, specifies the category of IP reputation, or, when IP intelligence is not enabled on the device, Unknown.
Continent
Displays the country in which the client is located.
State
Displays the state or province in which the client is located.
Access Profile
Displays the access profile used by the BIG-IP device for this session.
Using BIG-IQ Centralized Management, you can monitor all session activity originating from the Access profiles (also known as per-session policies) that you configured. The session count displayed in BIG-IQ includes both established and failed sessions. Use this report to determine which Access profiles are being used most frequently by your users in order to determine or troubleshoot resource allocation.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
With BIG-IQ, you can generate reports for sessions, grouped by the Access profile used, in order to gain information about which Access profiles are being used most heavily. The session counts displayed on the dashboard include both established and failed sessions.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Under Top 5 Access Profiles By Session Count, select an Access profile from the top right corner of the chart to add or remove an Access profile from view.
BIG-IQ Access allows you to monitor session data, grouped by Access profile used, from the Access Profile Usage dashboard. The session counts displayed on this dashboard include established and failed sessions. See the notes below to learn more about each category for which you can record data.
Using BIG-IQ, you may generate reports on session data for both user-defined and system-generated access control lists (ACLs). ACLs restrict user access to host and port combinations that are specified in access control entries (ACEs). You can create ACLs when configuring an Access Group, and BIG-IQ will also generate them automatically whenever you create a portal access resource, an app tunnel, or a a remote desktop configuration.
Generate reports on ACL usage by action count. You can also use BIG-IQ to view the session details associated with a particular ACL result, and view all log messages for both allowed and denied ACL results.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
Use the ACL Action Type dropdown to view results for one type of action.
Allow: Permit the traffic.
Continue: Skip checking against the remaining access control entries in this ACL and continue evaluation at the next ACL.
Discard: Drop the packet silently.
Reject: Drop the packet and send a TCP RST message on TCP flows or proper ICMP messages on UDP flows. Silently drop the packet on other protocols.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
For the Top 5 ACLs chart, select the name of an ACL in order to remove it or add it to the chart view.
BIG-IQ Access allows you to record and view Access Control List (ACL) usage data for an Access group or for a single managed BIG-IP device. See the notes below to learn more about the categories for which you can data.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
Select one of the options from the ACL Results dropdown menu to display sessions with a specific ACL result. By default, sessions with all ACL results display. You can show allowed results only or denied results only by showing the ACL RESULTS dropdown menu. Select All ACL Results to generate a report for sessions with all ACL results.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Click the blue session ID to open the Session Details screen, displaying session details and session variables.
Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
BIG-IQ Access allows you to record Access Control List (ACL) summary data for an Access group or for a single managed BIG-IP device. See the notes below to learn more about each category for which you can record data.
Displays the date and time that the ACL was created.
HostName
Displays the BIG-IP device name.
Session ID
Click the session ID to open the Session Details screen, displaying session details and session variables.
ACL Result
Displays ACL result: Allow, Continue, or Reject.
Src IP
Displays the source IP address.
Src Port
Displays the source port number.
Dest IP
Displays the destination IP address.
Dest Port
Displays the destination port number.
Virtual IP
Displays the IP address of the virtual server where the ACL originated.
Scheme
Displays the authorization scheme that corresponds to the ACL.
Host
Displays the host network that corresponds to the ACL.
Path
Displays the path to which the ACL belongs.
Partition
Displays the partition to which the ACL belongs. Only roles that are granted access to a partition can view the objects (such as the ACL) that the partition contains. If the ACL resides in the Common partition, all roles can access it.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
Select one of the options from the ACL Results dropdown menu to display sessions with a specific ACL result. By default, sessions with all ACL results display. You can show allowed results only or denied results only by showing the ACL RESULTS dropdown menu. Select All ACL Results to generate a report for sessions with all ACL results.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Click the blue session ID to open the Session Details screen, displaying session details and session variables.
Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
BIG-IQ Access allows you to record log messages for Access Control Lists (ACLs). See the notes below to learn more about each category for which you can record data.
You can monitor session data for session requests initiated by an IP address listed in the IP intelligence database. The IP intelligence database contains only IP addresses that are considered untrustworthy, as a result of having performed exploits or attacks. Learn more about the F5 IP intelligence database here: https://support.f5.com/csp/article/K41310205.
To BIG-IQ to record data for this metric, you will need to have configured an Access policy with an IP Reputation Lookup agent. This agent allows Access to search for the IP address in the IP intelligence database.
If a session is initiated from an IP with a bad reputation, this means that the IP address exists in the IP intelligence database and the session request will be blocked. For example, the IP address may be a spam source or an infected system. APM sets rules to identify IP reputation by default, based on category. If you discover any categories that are categorized as bad reputations that you find acceptable to initiate a session, you can update the iRule or create another iRule to allow the session. If the IP reputation is good, the IP address is not found in the IP intelligence database and the session request can go through.
Use Access to monitor all session requests initiated by IP addresses with a bad reputation. You can also use this workflow to determine the category of IP reputation and to view detailed session information.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Enable IP intelligence on you managed BIG-IP devices in order to populate the IP intelligence database.
Use BIG-IQ to view session data for IP addresses in the IP intelligence database.
Navigate to Monitoring > DASHBOARDS > Access > Sessions > Bad IP Reputation.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
From the IP REPUTATION RATIO (ALL SESSIONS) pie chart, select Bad to view session details for session requests originating from IP addresses in the IP intelligence database. You can view data such top client IPs, top countries which sessions are originating from, top users, top Access profiles, top virtual servers, and top Access policy results.
You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you were interested in viewing details on sessions originating from IP addresses in the intelligence database and originating from the United States, you would select Bad from the IP REPUTATION RATIO (ALL SESSIONS) pie chart and then select the dot over the United States in the map under TOP 10 COUNTRIES.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
BIG-IQ Access allows you to monitor APM sessions that originate from IP addresses that are present in the IP intelligence database. See the notes below to learn more about each category for which you can record data for
From the Access dashboards in BIG-IQ, you can view browser and operating system (OS) information, as well as detailed session information, for specific managed BIG-IP devices provisioned for Access usage or for all devices in an Access group. Use BIG-IQ to monitor data on which browsers and operating systems are being used to initiate session requests, and to view detailed session data per operating system.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
You can use BIG-IQ to view session data organized by browser and operating system information for a particular managed BIG-IP device or for all devices in an Access group.
Navigate to Monitoring > DASHBOARDS > Access > Sessions > Browser and OS.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To learn which browsers are most commonly being used to initiate sessions, view the data under the BROWSER VERSIONS BY SESSION COUNT chart.
In the OS PLATFORM VERSIONS BY SESSION COUNT chart, select one of the segments of the pie chart bars to view session details for that OS. Available session details include top client IPs using that OS, top countries initiating sessions from that OS, top users, top Access profiles, top virtual servers, top Access policy results, and detailed session information.
Note: You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about sessions originating from Windows 8 and using the same virtual server, you would select Win8 from the OS PLATFORM VERSIONS BY SESSION COUNT dashboard and then select the horizontal bar by the virtual server you are interested in under TOP 10 VIRTUAL SERVERS.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
BIG-IQ Access allows you to view session data, organized by browser and operating system details, for a particular Access device or for all devices in an Access group. See the notes below to learn more about each category for which you can record data.
Use BIG-IQ Centralized Management to view the distribution of sessions organized by geographic location. From this report, you can view a map representing the geographic origin of all sessions initiated within a specified time period, and obtain detailed information for each session represented in the report.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
Use BIG-IQ to generate a report to view the distribution of sessions organized by geographic location.
Navigate to Monitoring > DASHBOARDS > Access > Sessions > By Geolocation.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
To view session data by country, go to the map titled SESSION COUNT DISTRIBUTION ACROSS COUNTRIES. Use your cursor to move the view to the part of the map you are interested in, or use + and - to zoom in or zoom out.
To view session data for one country, click the colored dot on the country you are interested in.
A dashboard with data on the top client IP addresses, top users, top Access profiles, top virtual servers, top client platforms, and most common Access policy results will display.
Note: You can continue to drill down based on the information you are interested in. For example, if you were interested in session requests originating from the United States using the ca_policy an Access profile you have created for California residents, you would select the United States from the SESSION COUNT DISTRIBUTION ACROSS COUNTRIES, and then when the next dashboard loads, you would select your Access profile named /Common/ca_policy from under TOP 10 ACCESS PROFILES.
To exit the nested view or to move up one level, select the breadcrumbs links at the top of the dashboard you want to navigate to.
To view session data originating from a particular state or province, perform the same steps as above with the SESSION COUNT DISTRIBUTION ACROSS STATES chart.
BIG-IQ Access allows you view the distribution of all APM sessions by geographic location. See the notes below to learn more about each category you can record data for.
You can monitor the sessions that BIG-IQ® Centralized Management denies. By using the Access Monitoring option, you can view the following information:
The history of denied sessions
The reasons why sessions were denied
The top denied users, sorted by session count
The top authentication failures
The top denied policies
The top denied sessions by country of origin
The top denied session by the virtual server
The denied sessions, sorted by the client platform
From the ACCESS GROUP/DEVICE list at upper left, select Managed Devices, or one or more of these options:
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
From the DENIED SESSIONS/AUTH FAILURES OVER TIME chart, select or deselect Auth Failures or Denied Sessions from the top right corner of the chart to add or remove them from view.
From any of the bar charts, select one of the horizontal bars to view details such as the authentication failure categories, top 10 reasons for denied sessions, top 10 denied users, top 10 denied Access policies, top 10 virtual servers by denied sessions, and top 10 client platforms by denied sessions.
You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about LDAP failures associated with a particular Access policy, click the bar by the Access policy you are interested in under the chart TOP 10 DENIED POLICIES, then on the next screen, select the bar by LDAP Failure under the TOP 10 DENIED REASONS chart. The customized dashboard will display all LDAP failures that resulted in denied sessions and originated from a single Access policy.
To exit out of the nested view or to move up one level, select the blue links at the top with the dashboard you would like to navigate to.
From here, you can view details regarding denied sessions and create a report.
BIG-IQ Access allows you to monitor denied Access Control List (ACL) sessions data. See the notes below to learn more about each category for which you can record data.
Endpoint (client-side) security is a strategy for ensuring that a client device does not present a security risk before it is granted a remote-access connection to the network. Endpoint software verifies that desktop antivirus and firewall software is in place, systems are patched, keyloggers or other dangerous processes are not running, and sensitive data is not left behind in web caches and other vulnerable locations.
Use BIG-IQ Centralized Management to record and view data for the various endpoint security products used by APM users who initiate session requests. You can also view session details for each session where endpoint checks were performed.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
In the SOFTWARE CHECKS TYPE chart, select one of the horizontal bars to view details such as the users, endpoint check products, geolocation distribution, and client OS involved in this endpoint check.
You can continue drilling down in this dashboard to customize the view depending on what information you are interested in. For example, if you wanted to view details about antivirus checks initiated by the user Julie, you would select Antivirus from the SOFTWARE CHECKS TYPE dashboard and then select the horizontal bar by Julie’s name under the chart TOP 10 Users.
To exit out of the nested view or to move up one level, select the blue links at the top with the dashboard you would like to navigate to.
In the TOP 10 USED PRODUCTS chart, select a software check product that you would like to view details for. You may view details such as top users, vendor information, geolocation data, and client OS distribution, as well as session data.
You can continue drilling down in this dashboard to customize the view depending on what information you are interested in.
Exit out of the nested view when you are finished.
In the TOP 10 VENDORS USED chart, select a software check vendor that you would like to view details for. You may view details such as top users, software check product information, geolocation data, and client OS distribution, as well as session data.
You can continue drilling down in this dashboard to customize the view depending on what information you are interested in.
Exit out of the nested view when you are finished.
BIG-IQ Access allows you to monitor endpoint security check summary data for each established session. See the notes below to learn more about each category for which you can record data.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Choose to view logs of only one severity by selecting a value from the Log Level dropdown.
Use the Log Levels menu to sort by message severity. Selecting Emergency will show only the most severe warnings, and selecting Debug will display the lowest severity messages.
BIG-IQ Access allows you to monitor endpoint security check details for each established session. See the notes below to learn more about each category for which you can record data.
Use BIG-IQ Centralized Management to monitor APM license usage to monitor if you are close to your license usage limits for BIG-IQ APM. You can monitor the number of users with active Access sessions, Connectivity sessions, and Secure Web Gateway (SWG) sessions.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Select up to 5 managed BIG-IP devices from the hostname list in order to monitor the license usage originating from those devices.
To add or remove a managed BIG-IP device from any of the license usage charts, select the hostname in the top right corner of the chart.
BIG-IQ Access allows you to monitor APM session data filtered by license usage: APM usage, Connectivity usage, and Secure Web Gateway usage. From this page, you can generate customizable and dynamic reports to monitor license usage by managed BIG-IP device. See the notes below to learn more about each category for which you can generate data.
From BIG-IQ, you can monitor the number of new APM sessions over a specified period of time in order to measure recent traffic or to troubleshoot recent session issues. Use the new sessions dashboard to view the total number of established sessions, timed-out session requests, and denied session requests.
Before BIG-IQ can display Access report data for a managed BIG-IP device, you must first complete the following tasks:
Add the managed BIG-IP device to the BIG-IQ Centralized Management inventory
Discover and import the managed BIG-IP device
Have a BIG-IQ user enable Access remote logging configuration on the managed BIG-IP device
To discover and import a configuration and deploy configurations to a managed BIG-IP device, users must belong to one of the following RBAC roles:
Admin
Access Manager
Access Deployer
You can use BIG-IQ to generate reports on new sessions.
Navigate to Monitoring > DASHBOARDS > Access > Sessions > New Sessions.
At the top left of the screen, from the ACCESS GROUP/DEVICES list, either select one of the first two options (All Devices and All Managed Devices) or select one or more of the other options (<Access group name>, <Cluster display name>, or <Device name>).
All Managed Devices Includes all Access devices that are currently discovered.
<Access group name> Select to include all devices in the Access group.
<Cluster display name> Select to include the devices in the cluster.
<Device name> Select to include the device. You can select any device from Managed Devices, <Access group name>, or <Cluster display name>.
From the TIMEFRAME menu, specify a time frame:
Select a predefined time period. These range from Last hour to Last 3 months.
Set a custom time period. Select Between, After, or Before, and click the additional fields that display the set dates and times that support your selection.
To save report data in a comma-separated values (CSV) file, click the CSV Report button.
The CSV file downloads.
To refresh the data on this dashboard immediately, click Refresh. To configure an automatic refresh, click the arrow next to it and then select 1 minute, 5 minutes, or 10 minutes. You can also Disable automatic refresh from this menu.
Customize the NEW SESSIONS OVER TIME chart by selecting the session result you would like to view.
For example, if you would like to filter your view by new session requests that were unsuccessful, select Denied and Timed Out from the top right corner of the chart.
BIG-IQ Access allows you to monitor new session data filtered by result of the session request. See the notes below to learn more about each category for which you can generate data.
Displays the number of new sessions per day over a specified time period, organized by total sessions, established sessions, denied sessions, and timed out session requests.
Local Time
Displays the time and date of the new ACL session.
Established / min
Displays the number of sessions established per minute.
Denied / min
Displays the number of sessions denied per minute.
Time out / min
Displays the number of session timeouts per minute.
You configure alert rules to define the thresholds that establish when an alert is a warning and when it is critical. BIG-IQ sends you APM email alerts to notify you when these error and license usage metrics meet the thresholds you specify.
BIG-IQ displays the list of alert rules configured on this system.
To create a new Alert Rule for an Access Group or a single BIG-IP device, select Add.
You can also edit the default APM alert rules by clicking on default-access-health. Doing this will change the alerts for all devices managed by this BIG-IQ.
Add a unique name and a description for this alert rule.
Select Device access-health to configure this alert rule for APM.
Select the check box by each of the metrics for which you would like to receive monitoring alerts.
The metrics you can receive alerts for include: Network Access Reconnects, Network Access Errors, Bad IP Reputations, Denied Sessions, SAML - IdP Errors, SAML - SP Errors, Access Usage, Connectivity Usage, and SWG Usage.
For each metric you decide to receive alerts for, set a number of occurrences at which you would like to receive a warning alert and a number of occurrences at which you would like to receive a critical alert.
Click SNMP Traps to enable alerts sent from remote SNMP-enabled devices.
To send alerts to an email inbox, select the check box by Email. Enter the emails to receive the alerts in the box below separated by commas.
Under Devices, select the group of devices for which you would like to configure alerts. You can select an Access Group at this point.
Select the BIG-IP devices and use the arrows to move them between the boxes.
When you have finished, click Save & Close.
When you finish, you will start receiving alerts (either in BIG-IQ, or your email, or both) based on what you configured.
Before you can use BIG-IQ to monitor APM alerts, you must first create alert rules that define the thresholds that establish when an alert is a warning and when it is critical.
You can use BIG-IQ to monitor both current APM alerts and past APM alerts to determine trends with network access and connectivity issues.
Click Applications > ALERT MANAGEMENT > Active Alerts.
You can sort all active alerts by alert Level, Title, Start time, Type, Context, Reported Object, and Last Updated.
Sorting by Type can be particularly important when you are searching for alerts associated with the health of APM configurations.
Once APM alerts are inactive, they will move to the Alert History tab under Applications > ALERT MANAGEMENT.
From there, you can filter results by the last day and by the last two days from the dropdown menu in the top left in order to triage connection errors and other network issues for users of an APM connection.
You can monitor your user base by viewing the BIG-IQ Centralized Management Access user dashboard for data on specific users. The system displays which users created the most sessions, were denied the most sessions, and had the longest total session duration. You may use the user summary dashboard to view and monitor per-session and per-request data for all end-users accessing the network through an Access Policy, or for a specific user. Use this dashboard to troubleshoot connectivity and security issues for a specific user accessing the network.
Dashboard
Functionality
TOP 10 USERS BY SESSION COUNT
Displays the the top 10 most frequent users and the number of sessions per user. Click on a user to open a new screen that displays the user summary for that specific user.
TOP 10 USERS BY DENIED SESSION COUNT
Displays the top 10 users who most frequently attempted to start a session but were denied by the BIG-IQ system.
TOP 10 USERS BY TOTAL SESSION DURATION
Displays the top 10 users with the longest total session time for the selected timeframe.
Chart
Functionality
Session Dashboard
Displays session information, including the overall number or sessions, the number of denied sessions, and the overall session duration for the timeframe selected.
Client Information Dashboard
Displays the number of unique devices that established a session, the number of unique geographical locations from where the devices logged in, and the number of unique application URLs.
Network Access Dashboard
Displays network access information, including the total number of network access sessions, the total bytes transferred, and the overall session duration.
Federation Dashboard
Displays the total number of SAML assertions and OAuth tokens.
SESSION COUNTS OVER TIME
Displays the total number of sessions over time for the selected timeframe for this user, separated by Allowed and Denied sessions.
SESSION DURATION OVER TIME
Displays the total duration of each session for this user over time for the selected timeframe, separated by Allowed and Denied sessions.
TOP 10 CLIENT IP’S
Lists the 10 most common IP addresses the client used to access the network during the given timeframe. Select any one of these IPs to drill down and learn more information.
LOGON DEVICE DISTRIBUTION
Lists the geographic distribution of each logon device.
SESSION TERMINATION REASONS
Displays the most common reasons for session termination for this user. Select a termination reason to learn more about a type of termination, such as associated access policies, logon devices, and more.
IDENTITY FAILURES
Displays the identity and Federation failures coming from Active Directory, LDAP, RADIUS, HTTP, SAML, and OIDC.
DEVICE POSTURE FAILURES
Displays the failures associated with device posture checks, including but not limited to antivirus, firewall, and HW encryption. Select a failure to learn more about that failure type.
DENIED SESSION REASONS
Lists the denied session reasons for this user and the number of denied sessions for each category. Select a reason to learn more about this type of denial.
DENIED RADIUS (MFA) FAILURES
Displays the list of RADIUS multi-factor authentication failures for this user. Click on a failure to learn more.
TOP 10 ACCESS PROFILES
Lists the top 10 access profiles for this user. Select an access profile to see more data associated with this user’s activity on this access profile.
TOP 10 VIRTUAL SERVERS
Lists the top 10 virtual server IP addresses for this user and the number of times it has been used by this client during the selected timeframe. Select an IP address to learn more acount activity on a certain virtual server.
TOP 10 CLIENT PLATFORMS
Displays the top 10 operating systems this user is accessing the network from. Click a platform to drill down and learn more about user activity on this operating system.
TOP 10 ACCESS POLICY RESULTS
Lists the top 10 access polciies associated with this user’s network access. Select an access policy to learn more about this user’s activity associated with that policy or to determine which policy you may need to troubleshoot in the Configuration tab.
TOP 10 APPLICATIONS
Lists the top 10 applications the user has accessed on the network.
TOP 10 ENDPOINT SOFTWARE PRODUCTS
View the top 10 endpoint security products used by the client to access the network.
LOGON DISTRIBUTION BY LOCATION
View the geographic distribution of user logons from this map. Use this map to determine if a user may have logged on from different geographic locations during a single session.
Kill User Sessions
View the geographic distribution of user logons from this map. Use this map to determine if a user may have logged on from different geographic locations during a single session.