STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must generate event log records that can be forwarded to the centralized events log.

DISA Rule

SV-266146r1024841_rule

Vulnerability Number

V-266146

Group Title

SRG-NET-000492-ALG-000027

Rule Version

F5BI-AP-300018

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Note: Performing this Fix modifies the "default-log-setting" log profile, but users can use a different log profile for the Access Profile. However, this requires using the APM Module.

APM Default Log Profile:
From the BIG-IP GUI:
1. Access.
2. Overview.
3. Event Logs.
4. Settings.
5. Check the box for the "default-log-setting" and click "Edit".
6. Check "Enable Access System Logs".
7. On the "Access System Logs" tab, set all items are to "Notice".
8. Click "OK".

Access Profile Log Setting:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click the Name of the Access Profile.
5. Logs tab.
6. Move "default-log-setting" to the "Selected" column.
7. Click "Update".

Check Contents

APM Default Log Profile:
From the BIG-IP GUI:
1. Access.
2. Overview.
3. Event Logs.
4. Settings.
5. Check the box for the "default-log-setting" and click "Edit".
6. Verify "Enable Access System Logs" is checked.
7. On the "Access System Logs" tab, verify all items are set to "Notice".


Access Profile Log Setting:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click the Name of the Access Profile.
5. Logs tab.
6. Verify "default-log-setting" is in the "Selected" column.

If the BIG-IP appliance is not configured to generate log records, this is a finding.

Vulnerability Number

V-266146

Documentable

False

Rule Version

F5BI-AP-300018

Severity Override Guidance

APM Default Log Profile:
From the BIG-IP GUI:
1. Access.
2. Overview.
3. Event Logs.
4. Settings.
5. Check the box for the "default-log-setting" and click "Edit".
6. Verify "Enable Access System Logs" is checked.
7. On the "Access System Logs" tab, verify all items are set to "Notice".


Access Profile Log Setting:
From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles (Per-Session Policies).
4. Click the Name of the Access Profile.
5. Logs tab.
6. Verify "default-log-setting" is in the "Selected" column.

If the BIG-IP appliance is not configured to generate log records, this is a finding.

Check Content Reference

M

Target Key

5640