Skip to main content
Skip table of contents

F5 LTM Advanced Firewall Messages

Classification

Rule NameRule TypeCommon EventClassification
F5 LTM Advanced Firewall MessagesBase RuleGeneral Attack ActivityAttack
Advanced Firewall Connection ClosedSub RuleConnection ClosedNetwork Traffic
Advanced Firewall Connection EstablishedSub RuleConnection EstablishedNetwork Traffic

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
severity<severity>Number
action<action>Text/String
hostname<sname>Number/Text
dest_ip<dip>Number
dest_port<dport>Number
device_product<vendorinfo>Text/String
device_version<version>Number
ip_protocol<protname>Text/String
source_ip<sip>Number
source_port<sport>Number
source_user<login>Text/String
translated_dest_ip<dnatip>Number
translated_dest_port<dnatport>Number
translated_source_ip<snatip>Number
translated_source_port<snatport>Number
translated_vlan<dinterface>Text/String
vlan<sinterface>Text/String
action<tag1>Text/String
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.