F5 Advanced WAF Integration via Telemetry Streaming for Microsoft Sentinel

Solution: F5 Big-IP

F5 Big-IP Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher F5 Networks
Support Tier Partner
Support Link https://support.f5.com/csp/home
Categories domains
Version 2.0.1
Author F5 Networks
First Published 2022-05-25
Solution Folder F5 BIG-IP
Marketplace Azure Marketplace · Popularity: 🔵 Medium (66%)

The F5 BIG-IP Solution for Microsoft Sentinel allows you to easily connect your F5 logs with Microsoft Sentinel, to view dashboards, create custom alerts, and improve investigation. This gives you more insight into your organization's network and improves your security operation capabilities.

For more details about this solution refer to https://community.f5.com/t5/technical-articles/integrating-the-f5-bigip-with-azure-sentinel/ta-p/282868

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API

Additional Information

📖 Vendor Documentation: F5 BIG-IP Event Messages - Event messages and attack types

Contents

Data Connectors

This solution provides 1 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 4 table(s):

Table Used By Connectors Used By Content
F5Telemetry_ASM_CL 🔶 F5 BIG-IP Workbooks
F5Telemetry_AVR_CL - Workbooks
F5Telemetry_LTM_CL 🔶 F5 BIG-IP Workbooks
F5Telemetry_system_CL 🔶 F5 BIG-IP Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 2 content item(s):

Content Type Count
Workbooks 2

Workbooks

Name Tables Used
F5BIGIPSystemMetrics F5Telemetry_AVR_CL
F5Telemetry_system_CL
F5Networks F5Telemetry_ASM_CL
F5Telemetry_LTM_CL
F5Telemetry_system_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index