Bug ID 2449389: AFM DoS Network Events incorrectly show event=Attack None with attack ID=0 during active attacks.

Last Modified: Sep 02, 2026

Affected Product(s):
BIG-IP AVR(all modules)

Known Affected Versions:
17.5.1.5, 17.5.1.6, 17.5.1.8, 17.5.1.9

Opened: Aug 04, 2026

Severity: 4-Minor

Symptoms

Observed Attack ID=0 and event = Attack None in the Security > Event Logs > DoS > Network > Events page

Impact

The spurious logs are stored in the LogDB

Conditions

- Enable the TCP SYN Flood vector with the mitigation values configured as required. (Attached screenshot) - Generate traffic from the client using the following Scapy command: Command: send(IP(src="5.5.5.5", dst=<VS-IP>)/TCP(flags="S"), inter=0.005, loop=1) - Verify the events under: Security > Event Logs > DoS > Network > Events

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips