Skip to content

Integrate F5 BIG-IP LTM

You can integrate F5 BIG-IP LTM with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a F5 BIG-IP LTM integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure F5 BIG-IP LTM to send data to the data collector.

Requirements

The following is required for F5 BIG-IP LTM configuration:

  • Check the requirements for the data collector you are using by reviewing the guides at Data collectors.

Add a F5 BIG-IP LTM integration

To integrate F5 BIG-IP LTM, you must first install a Sophos XDR data collector, then configure F5 to send logs to it.

Install and configure a data collector

F5 BIG-IP LTM must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and turn on monitoring

When the data collector is ready, you can configure F5 BIG-IP LTM to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in F5's own guide: Configuring the BIG-IP system to log to a remote syslog server.
  2. Be sure the configured IP address matches the Sophos XDR data collector's server IP address.

Your F5 BIG-IP LTM data should now appear in the Sophos Data Lake after validation.