Useful F5 Log Queries
Introduction
If you work with F5 BIG-IP you maybe need to know for example when a cluster failover has happened or a user has done some changes.
The following will describe some useful F5 log queries which you can use on the F5 logs or any central syslog server you're sending the F5 logs to.
F5 LTM Log Queries
Check in the Admin UI at System - Logs: Local Traffic
Research | Log Query |
---|---|
Show cluster switchover of a F5 BIG-IP |
HA unit 1 state change
|
TMM is very busy or is stalled. K10095: Error Message: Clock advanced by <number> ticks
Any value higher than 1000 does show a problem with too high load. |
Clock advanced by
|
A Virtual Server is under high load Also see here: 01010038 : Syncookie counter %d exceeded vip threshold %u for virtual = %A:%d
If the message shows multiple times there's maybe an attack going on or a high load on the Virtual Server. |
Syncookie counter
Example output:
|
F5 Audit Log Queries
Check in the Admin UI at System - Logs: Audit: List
Research | Log Query |
---|---|
Show which user has done changes |
transaction
|