Configure VMware ESXi syslog forwarding using the vSphere client
You can configure VMware ESXi® to forward syslog data to Arctic Wolf using the .
These resources are required:
- An activated and dedicated Virtual Log Collector (vLC)
Note: Due to the high event volume observed during Early Access (EA) customer deployments, this integration requires a dedicated vLC to help maintain platform stability and performance and to reduce the risk of service disruptions caused by excessive log volume.
- Administrator access to VMware ESXi environments through the or
- Network connectivity between systems and the vLC
Configure the
Note: Repeat these steps for each ESXi host that you want Arctic Wolf to monitor.
- Sign in to the with administrator permissions, using the URL format
https://vsphere_server/ui. - Navigate to Hosts and Clusters.
- Select the applicable ESXi host.
- Navigate to .
- In the Key column filter, search for Syslog.global.logHost.
- Set the value to the vLC destination using the format
udp://vlc_ip:514. - In the Key column filter, search for Syslog.global.logLevel.
- Set the logging level to info.
- Save the changes.