secops_dashboard log profile
The security monitoring dashboard depends on a consistent set of fields being present on every security event. The secops_dashboard log profile is the guarantee of that consistency: it ensures every data plane forwards the same set of fields, so the dashboard can render every event correctly.
The secops_dashboard log profile is a pre-configured, system-managed F5 WAF for NGINX log profile that captures the security telemetry fields the NGINXaaS Console security monitoring dashboard expects. It is the default log profile used by the security dashboard.
The secops_dashboard log profile is the only log profile guaranteed to produce data the security dashboard can render correctly. Other log profiles can coexist with it and continue to serve other logging destinations such as Security Information and Event Management (SIEM) systems, file logs, or custom syslog endpoints, but they are not interpreted by the security dashboard.
This document covers what the secops_dashboard log profile is and when to use it. For the steps to deploy it as part of setting up an instance, see Set up security monitoring.
For more information, see: