F5 Advanced WAF / ASM Capture Guide For Unified aiFObserve
Best Capture Source
Use F5 Advanced WAF or ASM request/security logging profiles. Send logs to a remote syslog/SIEM collector or export structured logs from your logging pipeline.
Basic Logging
- request timestamp
- support ID or request ID
- client IP and port
- destination IP and port
- virtual server
- policy name
- host
- URL
- method
- response code
- request status/action
- violation or attack type
- severity
- user agent
- request length and response length, if available
Extended Logging
- application/security policy ID and version
- blocking setting and enforcement mode
- signature ID and signature name
- matched parameter, object, or header, sanitized as needed
- login page/session/user tracking fields if enabled
- geolocation fields
- X-Forwarded-For and trace/request ID headers
- pool/member/backend fields
- HTTP protocol and TLS/SNI fields
User And App Identity
- F5 session/user tracking fields
- identity headers from upstream authentication
- virtual server, policy, host, URL
- user agent
For AI apps and APIs, preserve route and host fields so provider detection does not depend only on IP address.
AI Provider And Location Evidence
Keep virtual server, backend/pool, host, SNI, URL, and geolocation. These fields support application ownership and data boundary checks.