Applies To:
Show VersionsBIG-IP AFM
- 14.1.2, 14.1.0
Configuring High-Speed Remote Logging of DoS Events
Overview: Configuring DoS Protection event logging
You can configure the BIG-IP® system to log information about BIG-IP system denial-of-service (DoS) events, and send the log messages to remote high-speed log servers.
This illustration shows the association of the configuration objects for remote high-speed logging of DoS Protection events.
Association of remote high-speed logging configuration objects
Task summary
Perform these tasks to configure logging of DoS Protection events on the BIG-IP® system.About the configuration objects of DoS protection event logging
When configuring remote high-speed logging of DoS Protection event logging, it is helpful to understand the objects you need to create and why, as described here:
Object | Reason | Applies to |
---|---|---|
Pool of remote log servers | Create a pool of remote log servers to which the BIG-IP® system can send log messages. | Creating a pool of remote logging servers. |
Destination (unformatted) | Create a log destination of Remote High-Speed Log type that specifies a pool of remote log servers. | Creating a remote high-speed log destination. |
Destination (formatted) | If your remote log servers are the ArcSight, Splunk, IPFIX, or Remote Syslog type, create an additional log destination to format the logs in the required format and forward the logs to a remote high-speed log destination. | Creating a formatted remote high-speed log destination. |
Publisher | Create a log publisher to send logs to a set of specified log destinations. | Creating a publisher. |
DNS logging profile | Create a custom DNS logging profile to define the data you want the BIG-IP system to include in the DNS logs and associate a log publisher with the profile. | Creating a custom DoS Protecttion Logging profile. |
protected object (also called virtual server) | Associate a custom DNS profile with a protected object to define how the system logs the DNS traffic that the protected object processes. | Configuring a protected object to perform DoS Protection event logging. |
Creating a pool of remote logging servers
Creating a remote high-speed log destination
Create a log destination of the Remote High-Speed Log type to specify that log messages are sent to a pool of remote log servers.
Creating a formatted remote high-speed log destination
Create a formatted logging destination to specify that log messages are sent to a pool of remote log servers, such as Remote Syslog, Splunk, or IPFIX servers.