Operations

Auditing

The product maintains an audit log of administrative actions performed in the user interface. The audit log is intended for accountability and forensic review.

Auditing page

Figure 8. The Auditing page lists timestamp, user, role, and description for each recorded action.

To work with the audit log:

  1. Go to System > Auditing.

  2. Use the time-range, user, and free-text filters to narrow the displayed records.

  3. Select Export to export the records for archival or external review.

  4. Select Delete to remove selected records.

Troubleshooting

The Troubleshooting view exposes service logs for diagnostic purposes.

Troubleshooting page

Figure 9. The Troubleshooting page displays the current log level and provides controls to set the log level, refresh logs, delete logs, and download a debug bundle.

Access the logs

  1. Go to System > Troubleshooting.

  2. Use the log_level, log_source, and free-text filters to narrow the displayed entries.

  3. Select Load More Logs to extend the visible window.

Manage log level

To change the active log level (for example, from INFO to DEBUG for diagnostic purposes), select Set Log Level and select the desired level. Return the log level to INFO after troubleshooting is complete to limit log volume in production.

Download debug bundle

To export a diagnostic bundle for inclusion in a support case, select Download Debug Logs. The bundle contains the local log store and is suitable for sharing with F5 Support.

Common diagnostic scenarios

Symptom

Recommended steps

The user interface does not load on https://<host-ip>:8000

Verify that the host firewall permits TCP 8000 and that all services report a healthy state.

The ingestion counter does not increase after BIG-IP integration

Confirm BIG-IP can reach the Collector on TCP 6514. Confirm serverssl is attached to the Internal Logging Virtual Server. Confirm the iRule references the correct Internal Logging Pool name and is attached to the API Virtual Server.

Endpoints do not appear despite active ingestion

Wait for the next analysis cycle. Confirm that the relevant domains are not disabled in Manage > Domains.

A block action fails

Confirm management connectivity status on Integration > BIG-IPs. Verify the WAF policy supports scheme differentiation. See Known issues in the API Security Local Edition Release Notes.

An upgrade fails on Docker Compose

Re-run the upgrade with --dry-run and review the output. Confirm the host meets sizing guidance obtained from F5.

For unresolved issues, download the debug bundle and contact F5 Support with the bundle attached.