Integrate F5 BIG-IP LTM
You can integrate F5 BIG-IP LTM with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.
Key steps
The key steps in a F5 BIG-IP LTM integration are as follows:
- Install and configure a data collector if you haven't already done so.
- Configure F5 BIG-IP LTM to send data to the data collector.
Requirements
The following is required for F5 BIG-IP LTM configuration:
- Check the requirements for the data collector you are using by reviewing the guides at Data collectors.
Add a F5 BIG-IP LTM integration
To integrate F5 BIG-IP LTM, you must first install a Sophos XDR data collector, then configure F5 to send logs to it.
Install and configure a data collector
F5 BIG-IP LTM must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.
Configure logging and turn on monitoring
When the data collector is ready, you can configure F5 BIG-IP LTM to send us data.
To set up event forwarding via syslog, do as follows:
- Follow the steps in F5's own guide: Configuring the BIG-IP system to log to a remote syslog server.
- Be sure the configured IP address matches the Sophos XDR data collector's server IP address.
Your F5 BIG-IP LTM data should now appear in the Sophos Data Lake after validation.