betawiz,
Is there a reason you have configured BIG-IP to replace the source IP address (also known as SNAT'ing)?
Some customers do in fact need to enable SNAT on their BIG-IP to assist in routing, however it is not always required. I would first find out if you need SNAT or not. If not, disable it, and BIG-IP will not modify the source IP at all.
If you do need SNAT, then your best bet is to have the BIG-IP inject the true source IP address into the X-forwarded header, and then configure IIS to log based upon the IP in the header, and not the source IP of the packet.
Its not as scary as it sounds ;). This SOL has all the details -> https://support.f5.com/kb/en-us/solutions/public/4000/800/sol4816.html
Please, feel free to contact me if you need some assistance with this.
Regards, Ryan
F5 networks