F5 Distributed Cloud > F5 Distributed Cloud: Web Application Security & Scanning Source | Edit on
Lab 5: AI Assistant and Security Operations¶
Objective:
Provide summarization of security events.
Quickly provide details on how many attacks have happened and mitigation techniques applied.
Narrative:
As ACME corp has continued to protect their web applications, leaders within the organization has made requests for summaries of how ACME’s security investments are protecting the environment. ACME corp has made investments in SIEM technologies and F5 Distributed Cloud can export logs to external SIEMs. However not everyone in the ACME organization has experience building dashboards and running complex queries. After speaking with ACME Corp’s F5 SE, F5 Distributed Console has an AI assistant in the SaaS console that can provide answers quickly using natural language.
Note
Expected Lab Time: 10 minutes
Lab 5 Summary-AI Assistant & Security Operations: Finally, explore the AI Assistant feature in the F5 Distributed Cloud console to streamline security operations. Instead of manually sifting through logs and events, you’ll use natural language queries to have the AI quickly summarize recent security events, answer questions like “how many attacks were blocked in the last 24 hours,” and even explain specific incidents. This lab showcases how AI-driven insights can help validate that your WAF and other protections are working (i.e., how many SQL injection attempts were stopped) and provide management-friendly summaries. It underlines the value of an integrated platform where observability and analytics are built in, making it easier to monitor and communicate the application’s security status.
Task 1: Exploring AI Assistant¶
In this task you will utilize the AI assistant to explore security events. The AI assistant brings several intelligent capabilities to simplify management and security of apps and APIs using a natural language interface, including:
|
Show requests with WAF security events for the last 24 hours for load balancer
[<your-namespace>-lb] in namespace [<your-namespace>]
Note Be sure to replace [lb-name] with your adjective-animal-lb and [namespace] with adjective-animal of your lab.
Show SQL injection and directory traversal attacks in the last 24 days for load balancer
[<your-namespace>-lb] in namespace [<your-namespace>]
Note Be sure to replace [lb-name] with your adjective-animal-lb and [namespace] with adjective-animal of your lab.
|
By leveraging AI Assistant, network security operators can quickly investigate security events. The AI Assistant can also provide summary details natively in platform without requiring a third party visibility platform as observability is native to Distributed Cloud.
End of Lab 5: This concludes Lab 5. Feel free to review and the following video for more information about AI Assistant. https://www.youtube.com/watch?v=vaGygSkQOso
A Q&A session will begin shortly to conclude the overall lab.









