View NGINX Gateway Fabric security events
F5 NGINX Instance Manager shows F5 WAF security events from NGINX Gateway Fabric deployments in the Security Dashboard. NGINX Gateway Fabric’s NGINX Agent v3 includes a built-in OpenTelemetry collector that exports security events directly to NGINX Instance Manager. You don’t need NGINX Agent v2 to see F5 WAF activity on your NGINX Gateway Fabric instances.
You can view:
- F5 WAF security violations
- Bot detection events
- Policy violations
- Attack patterns
- Security event history
Important: Event visibility onlyThis integration covers security event visibility only. NGINX Instance Manager can’t manage NGINX Gateway Fabric instances, instance groups, or F5 WAF policy deployments. F5 plans to add full NGINX Agent v3 support for these capabilities in a future release.
- NGINX Instance Manager 2.23 or later
- NGINX Gateway Fabric running F5 WAF for NGINX with NGINX Agent v3, connected to NGINX Instance Manager. See Connect NGINX Gateway Fabric to NGINX Instance Manager.
- Security Monitoring turned on in NGINX Instance Manager
NGINX Gateway Fabric generates and exports security events. NGINX Instance Manager doesn’t pull or request them. Configure the export on the NGINX Gateway Fabric side.
This integration doesn’t require changes to Gateway API resources.
See Export security logs to F5 NGINX Instance Manager.
Go to WAF > Security Dashboard in NGINX Instance Manager. The dashboard has four tabs: Main, Bots, Advanced, and Event Logs. These tabs cover aggregate attack statistics, bot activity, signature and threat detail, and individual events.
Use Event Logs for individual event details, including source IP, URI, and Support ID.
You can filter events across all four tabs by fields including instance, instance group, IP address, policy, signature, severity, and Support ID.