Manual Chapter :
Configuring High-Speed Remote Logging of DNS DoS events
Applies To:
Show VersionsBIG-IP AFM
- 14.0.1, 14.0.0
Configuring High-Speed Remote Logging of DNS DoS events
Configuring High-Speed Remote Logging of DNS DoS events
Creating a pool of remote logging servers
Before creating a pool of log servers, gather the IP addresses of the servers that
you want to include in the pool. Ensure that the remote log servers are configured to
listen to and receive log messages from the BIG-IP
system.
Create a pool of remote log servers to which the BIG-IP system can send log
messages.
Creating a remote high-speed log destination
Before creating a remote high-speed log destination, ensure that at least one pool
of remote log servers exists on the BIG-IP system.
Create a log destination of the Remote High-Speed Log type to specify that log messages are sent to a pool of remote log servers.
Creating a formatted remote high-speed log destination
Ensure that at least one remote high-speed log destination exists on the BIG-IP system.
Create a formatted logging destination to specify that log messages are sent to a pool of remote log servers, such as Remote Syslog, Splunk, or IPFIX servers.
Creating a publisher
Ensure that at least one destination associated with a pool of remote log servers
exists on the BIG-IP system.
Create a publisher to specify where the BIG-IP system sends log messages for
specific resources.
Creating a custom DNS DoS protection logging profile
Create a custom logging profile to log DNS DoS
events and send the log messages to a specific location.
Now you created a logging profile so that the BIG-IP® system can log messages about SIP DoS
events and send the log messages to a pool of IPFIX collectors.
Assign this custom DNS DoS logging profile to a
protected object.
Logging DoS events for a protected object
Ensure that at least one log publisher exists on the BIG-IP system.
Assign a custom logging profile to a
protected object when you want the system to log DoS events for the traffic the
protected object processes.
The system logs DoS
events for the protected object.
You can review DoS
event logs at
and select the type of DoS event log to view.Disabling DNS DoS logging
Disable DNS DoS logging when you no longer want
the BIG-IP system to log information about the DNS traffic handled by the resources to
which the logging profile is assigned.
The system does not log DNS traffic handled by the resources to which this profile is
assigned.