BIG-IP Audit and System Log Files

  1. Audit Log

Log File Name: audit

Location:

Folder : /var/logs

GUI : System → Logs → Audit

Details: Audit logs in BIG-IP record user login and logout events, configuration changes made (via GUI, CLI, or API), command executions, and system-level actions such as module provisioning and license updates. These logs are essential for security auditing, ensuring compliance with standards (eg., PCI-DSS and HIPAA), troubleshooting unauthorized changes, and tracking administrative activities.

  1. System Logs

Log File Name: messages

Location:

Folder : /var/logs

GUI : System → Logs → System

Details: System logs include system messages, daemon logs, startup and shutdown events, resource usage warnings, interface or link status changes, and issues related to licensing and module provisioning. System logs are used to monitor and troubleshoot the overall health and operation of the system.