Skip to content

F5 BIG-IP LTM

You can integrate F5 BIG-IP Local Traffic Manager (LTM) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

F5 BIG-IP LTM product overview

F5 BIG-IP LTM is an application delivery controller that load-balances and manages application traffic across servers and clouds to keep applications available and scalable, including SSL/TLS offload, traffic steering and health monitoring, and protection against DDoS attacks.

What we ingest

Sophos XDR collects F5 BIG-IP LTM syslog data by listening for messages your appliance forwards to a Sophos XDR data collector. The following log categories are collected:

  • Authentication: Administrative and system authentication activity on the appliance.
  • Configuration and management: Management and configuration activity on the appliance, including CLI (TMSH) audit, shell and process activity, and system service events.

Event and data types

We ingest the following event and data types from F5 BIG-IP LTM:

  • Authentication: Administrative and system authentication events on the appliance, including login and password-check activity, with user and result. Normalized to authentication telemetry.
  • Configuration and management: Configuration and management activity, including TMSH CLI audit commands, shell and process activity, system and service events, and sensitive operations such as private-key export. Normalized to management event telemetry.

Data provided by this integration

Data provided by F5 BIG-IP LTM gets normalized to the following schemas:

  • auth
  • managementevent

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation