Integrate F5 BIG-IP LTM
You can integrate F5 BIG-IP LTM with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.
Key steps
The key steps in a F5 BIG-IP LTM integration are as follows:
- Install and configure a data collector if you haven't already done so.
- Configure F5 BIG-IP LTM to send data to the data collector.
Requirements
The following is required for F5 BIG-IP LTM configuration:
- Check the requirements for the data collector you are using by reviewing the guides at Data collectors.
Add a F5 BIG-IP LTM integration
To integrate F5 BIG-IP LTM, you must first install a Sophos XDR data collector, then configure F5 to send logs to it.
Install and configure a data collector
F5 BIG-IP LTM must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.
Configure logging and enable monitoring
When the data collector is ready, you can configure F5 BIG-IP LTM to send us data.
To set up event forwarding via syslog, do as follows:
- Follow the steps in F5's own guide: Configuring the BIG-IP system to log to a remote syslog server.
- Be sure the configured IP address matches the Sophos XDR data collector's server IP address.
Your F5 BIG-IP LTM data should now appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during F5 BIG-IP LTM configuration:
- You can configure multiple instances of F5 to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of F5.
Additional resources
For more information on configuring F5 BIG-IP LTM, see the following documents: