Updated Date: 07/07/2026
Logging DoS Protection events
You enable DoS logging to send DoS events from your BIG-IP devices and virtual servers to your Data Collection Device (DCD).
When you provision DoS Protection on a managed BIG-IP device, you can automatically configure the necessary objects that allow BIG-IP to send DoS event messages directly to BIG-IQ. During the automated process, the following objects are created to ensure secure remote logging from the host BIG-IP device:
-
One or more Logging Profiles
-
Log Publisher
-
Log Destination
-
Pool for each device
-
Pool Members
-
Pool Monitor
Note: To configure a log profile manually, see Configure DoS Protection event logging.
-
To automatically configure a logging profile to a managed BIG-IP device:
-
Click Configuration > SECURITY > Shared Security > DoS Protection > Device DoS Configurations.
The Device DoS Configurations screen opens.
-
Select one or more devices for DoS logging.
-
Click more an Configure DoS Logging.
-
Click Continue.
The system will generate the listed objects to your BIG-IP device, as required for remote logging to the primary DCD in your system setup. To view these objects, select the device’s row in the Device DoS Configurations screen, and the connected objects to your selection will appear in the panel at the bottom of the screen.
-
-
To automatically configure a logging profile to a Shared Security virtual server:
-
Click Configuration > SECURITY > Shared Security > Virtual Servers.
-
Select one or more virtual servers for DoS logging.
-
Click More and select Configure DoS Logging.
-
Click Continue.
The system will generate the listed objects to your virtual server, as required for remote logging to the primary DCD in your system setup. To view these objects, select the device’s row in the Virtual Servers screen, and the connected objects to your selection will appear in the Logging Profiles area of th panel at the bottom of the screen.
-
-
You can disable active existing logging configurations by selecting the check box next to the device or virtual server click Disable DoS Logging (or More > Disable DoS Logging).
To view or manage your logging profile, go to Configuration > SECURITY > Shared Security > Logging Profiles and select your DoS logging profile name.
Your system is now able to receive DoS event messages from BIG-IP. You can view this data by going to Monitoring > DASHBOARDS > DDoS > Protection Summary.
Important: For managed devices running versions earlier than 13.1.0.5, you can only view events from Monitoring > Events > DDoS screens.
To ensure that data is load balanced among your DCD devices, you must change the remote log destination. For more information see Edit log publisher destinations.
Note: Once you have completed this process, ensure that all your changes to your Local Traffic and Shared Security virtual servers are deployed over the host BIG-IP device. You can deploy your changes by going to, Deployment > EVALUATE & DEPLOY > Local Traffic & Network Deployment > EVALUATE & DEPLOY > Shared Security
BIG-IQ receives DoS Protection events from BIG-IP via it’s Data Collection Devices (DCD). To optimize the process, while ensuring high availability, it is best to load balance log events to a remote logging pool of DCDs . This will prevent data loss, in the instance that a DCD becomes unavailable, without unnecessary duplication of information.
While DoS Protection has an automated process for creating a logging profile, and its associated objects, you need manually add your DCD pool to the Log Publisher’s destination list.
To complete this process for DoS Protection, you must have previously configured the following:
- An imported and discovered BIG-IP device that hosts Dos Protection and its logging profile.
- A remote logging pool of DCDs configured to the service port number
8020.
For more information about configuring a remote pool of DCDs, see Connect Devices to a Data Collection Device Cluster in the Planning and Implementing a BIG-IQ Deploymentguide at support.f5.com.
Note: If you have already created or imported your logging profile, use this process to adjust the existing settings to include the remote logging pool of DCDs.
You must create a remote logging pool for the DCDs configured to the service port of your module. For more information see Connect Devices to a Data Collection Device cluster in the Planning and Implementing a BIG-IQ Deployment guide at support.f5.com.
Create a Remote High-Speed Log and Splunk-type Log Destination to specify that log messages are sent to your pool of DCDs.
-
At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Destinations.
The Log Destinations screen displays a list of the log destinations that are defined on this device.
-
Click Create.
-
Type a unique Namefor this destination.
-
From the Type list, select Remote High-Speed Log
-
From the Protocol list, select TCP.
-
From the Device list, select the BIG-IP device that hosts your service module’s policy or profile.
-
From the Pool list, select your pool of DCDs.
-
Click Save & Close.
The Log Destinations screen opens.
-
Click Create.
-
Type a unique Name for this destination.
-
From the Type list, select Splunk.
-
Under the Forward To field, select Remote High-Speed Log, and select the Remote High-Speed log saved in step 8.
-
Click Save & Close.
You have now designated your DCD pool as a remote destination for BIG-IP to send its logging data. If your system has multiple modules that require event logging, ensure that you repeat this process for the module’s designated DCD pool.
Create a Log Publisher to specify that BIG-IP system sends log messages to BIG-IQ. When configuring your Log Publisher ensure you are adding the Splunk-type Log Destination.
Before you configure monitoring of DoS events, you need to ensure that the DoS Protection service is enabled on the DCD.
Verify this by reviewing the services installed on the DCD on the BIG-IQ Data Collection Devices screen. Click System > BIG-IQ DATA COLLECTION > BIG-IQ Data Collection Devices.
If the DoS Protection service is not running, click Activate to start it.
Note: If you deactivate the DoS Protection service for a DCD, or remove a DCD with that service enabled, the associated pool member will be removed from the pool when you next deploy to the BIG-IP device (or devices). The pool dos-remote-logging-pool_*big-ipname* contains the pool member for the specified BIG-IP device.
You configure the collection and viewing of DoS events so that you can better view and monitor information about your DoS protection. The BIG-IQ Centralized Management system provides a single-button configuration process that creates and configures the needed configuration objects. The system automatically creates the following configuration objects, if needed:
- One or more logging profiles
- A log publisher
- A log destination
- A pool for each device
- Pool members
- A pool monitor
-
Click Configuration > SECURITY > Shared Security > Virtual Servers.
-
In the list, select the check box to the left of the object that will host the logging profile.
-
Click Manage Logging and select Configure DoS Logging.
The DoS Logging Configuration dialog box opens.
-
In the dialog box, click Continue.
The dialog box shows the configuration status, including which objects were created.
-
Click Close.
-
Use the Deployment screens to deploy the BIG-IP device associated with the virtual server using the Local Traffic service using these steps.
-
Click Deployment > EVALUATE & DEPLOY > Local Traffic & Network.
-
In the Deployments area, click Create.
-
Specify a Name and Description, and select the appropriate deployment options.
-
In the Target Device(s) area, select the device used by the application and click Create.
The deployment causes some of the objects created by the DoS logging configuration process to be deployed to the device.
-
-
Deploy the same BIG-IP device using either the Network Security or Web Application Security service using these steps.
You can use either service since both include the Shared Security objects.
-
Click Deployment > EVALUATE & DEPLOY > Network Security or Deployment > EVALUATE & DEPLOY > Web Application Security.
-
In the Deployments area, click Create.
-
Specify a Name and Description, and select the appropriate deployment options.
-
In the Target Device(s) area, select the device used by the application and click Create.
The deployment causes the rest of the objects created by the DoS logging configuration process to be deployed to the device.
-
You have now configured your logging profile to send DoS Protection events from the BIG-IP devices associated with the virtual servers. Once you have deployed your changes, you can view these events on Monitoring > EVENTS > DoS screens.
To ensure that data is load balanced among your DCD devices, you must change the remote log destination. For more information see Edit log publisher destinations.
Note: Once you have completed this process, ensure that all your changes to your Local Traffic and Shared Security virtual servers are deployed over the host BIG-IP device. You can deploy your changes by going to, Deployment > EVALUATE & DEPLOY > Local Traffic & Network Deployment > EVALUATE & DEPLOY > Shared Security
You must have created the log destination before you can add it to the an existing Log Publisher. For more information see Managing Logs in support.f5.com.
Edit the Log Publisher destination settings to change the pools that receive remote logging messages from BIG-IP.
-
At the top of the screen, click Configuration, then, on the left, click LOCAL TRAFFIC > Logs > Log Publishers.
The screen displays a list of the Log Publishers that are defined on this device.
-
Select the name of the log publisher you wish to edit.
The log publisher properties screen opens.
-
To add log destinations, select the Log Destination(s) from the Available list and use the arrow to move your selection to the Selected list.
You can filter the Available list by selecting the type of destination from the drop-down list.
-
To remove log destinations, select the Log Destination(s) from the Selected list and use the arrow to move your selection to the Available list.
-
Click Save & Close
You have changed the remote destinations associated with the Log Publisher. This will alter where the BIG-IP device sends its log data.
Deploy changes to your BIG-IP device.