F5 BIG-IP - use cases for Sentinel

Georgi Palazov 286 Reputation points
2022-10-17T05:53:07.177+00:00

Hello,

We have integrated F5 BIG-IP for a customer, but there are no use cases for Sentinel. It didn't seem to have in the Content Hub, nor in GitHub.
Have anyone written any KQL for F5 BIG-IP?

The following tables seem to produce valuable information, imo:
250914-image.png

Microsoft Security | Microsoft Sentinel
0 comments No comments
{count} votes

Accepted answer
  1. David Broggy 6,371 Reputation points MVP Volunteer Moderator
    2022-10-18T03:27:33.91+00:00

    Hi ppal,
    Sadly F5 hasn't done much to improve their support for Sentinel.
    What I'm seeing in google and youtube is likely the same stuff you're finding.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Antony Millington 0 Reputation points
    2023-09-27T10:07:11.3733333+00:00

    Hi Georgi,

    yes F5 do have workbooks in the Content Hub. They cover system reporting, ASM and traffic statistics. The reporting from F5 into the Sentinel Log Analytics workspace is excellent though, so simple Kusto queries can give you most stuff you need to generate your own workbooks. You just need to make sure you have setup logging to Azure via Telemetry Streaming and that everything you need is being pushed to the log destination pointing to Azure.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.