Uploaded August 2026 | Updated September 2026, 2 hours ago
Learn how to bridge the visibility gap between your F5 NGINX WAF and your Security Operations Center (SOC) with our native Splunk integration, managed through the F5 NGINX One Console.
In this demonstration, we walk you through the process of configuring and deploying a Splunk-ready log profile in just a few clicks. See how the NGINX One Console simplifies sending detailed WAF security events directly to your Splunk instance, eliminating the need for manual configuration and custom log formats.
We'll showcase how to:
1) Create and deploy a Splunk log profile using the NGINX One Console's GUI.
2) Simulate common web attacks (Command Injection and XSS) against a protected application.
3) Instantly visualize and analyze the security events in a native Splunk dashboard.
4) Trace specific security events using the support ID for rapid forensic analysis.
Timestamps
0:00 - Introduction
0:05 - The Visibility Gap Between WAF and SOC Operations
0:35 - Solution: Closing the Gap with NGINX One Console
1:05 - NGINX One Console Dashboard Overview
1:25 - How to Create a Splunk Log Profile
2:11 - Deploying the Log Profile to an NGINX Instance
2:47 - Live Attack Simulation (Command Injection & XSS)
3:28 - Reviewing WAF Events in the Splunk Security Dashboard
4:05 - Analyzing Forensic Details of Blocked Attacks
4:45 - Key Benefits: Faster Integration, Less Overhead, Better Visibility
5:12 - Conclusion
Notes:
- Contributed by: Akash Ananthanarayanan
- Related Article: None
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Chase Abbott: linkedin.com/in/chaseabbott1
Learn how to bridge the visibility gap between your F5 NGINX WAF and your Security Operations Center (SOC) with our native Splunk integration, managed through the F5 NGINX One Console.
In this demonstration, we walk you through the process of configuring and deploying a Splunk-ready log profile in just a few clicks. See how the NGINX One Console simplifies sending detailed WAF security events directly to your Splunk instance, eliminating the need for manual configuration and custom log formats.
We'll showcase how to:
1) Create and deploy a Splunk log profile using the NGINX One Console's GUI.
2) Simulate common web attacks (Command Injection and XSS) against a protected application.
3) Instantly visualize and analyze the security events in a native Splunk dashboard.
4) Trace specific security events using the support ID for rapid forensic analysis.
Timestamps
0:00 - Introduction
0:05 - The Visibility Gap Between WAF and SOC Operations
0:35 - Solution: Closing the Gap with NGINX One Console
1:05 - NGINX One Console Dashboard Overview
1:25 - How to Create a Splunk Log Profile
2:11 - Deploying the Log Profile to an NGINX Instance
2:47 - Live Attack Simulation (Command Injection & XSS)
3:28 - Reviewing WAF Events in the Splunk Security Dashboard
4:05 - Analyzing Forensic Details of Blocked Attacks
4:45 - Key Benefits: Faster Integration, Less Overhead, Better Visibility
5:12 - Conclusion
Notes:
- Contributed by: Akash Ananthanarayanan
- Related Article: None
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Chase Abbott: linkedin.com/in/chaseabbott1










