• F5 resolved a Distributed Cloud Global Log Receiver degradation on 6 September after the incident affected one customer from the previous day
  • Customer traffic and Distributed Cloud Console services remained operational, while F5 did not say whether affected logs were delayed, lost or later recovered

The Fact

F5 resolved an incident affecting its Distributed Cloud Global Log Receiver at 07:54 UTC on 6 September. The company had been investigating reports of service degradation since 5 September.

F5 said the impact was limited to one customer, which it contacted directly. It also said customer traffic was unaffected and Distributed Cloud Console services remained operational. The Global Log Receiver is used to receive log data, so the reported problem concerned log delivery rather than the underlying application traffic.

A third-party status tracker recorded about 12 hours and 50 minutes between detection and resolution. That period represents the incident-monitoring window and does not mean customer traffic was unavailable for that length of time.

The assessment

For the affected customer, the problem was not getting application traffic through F5. It was receiving the logs used to see and investigate what was happening around that traffic. Applications could remain available while the information used by security and operations teams was degraded.

Recovery therefore involves more than bringing the receiver back online. The customer also needs to know what happened to logs generated during the incident: whether they arrived late, were dropped or became available after the service recovered. F5's status update does not provide that detail, so it does not establish that any log data was permanently lost.

For BTW readers, traffic uptime alone would have missed this incident. Teams using the service need to monitor log delivery separately if those records are part of their security investigations or operational checks.

What to watch

Watch for F5 to explain whether logs generated during the incident were delayed, dropped or recovered after service returned, and whether it publishes a root cause. Any repeat degradation affecting the Global Log Receiver would also help establish whether this was an isolated customer incident or a recurring service problem.