Configure VMware ESXi syslog forwarding using the ESXi Host Client
You can configure VMware ESXi to forward syslog data to Arctic Wolf using the ESXi Host Client.
These resources are required:
- An activated and dedicated Virtual Log Collector (vLC)
Note: Due to the high event volume observed during Early Access (EA) customer deployments, this integration requires a dedicated vLC to help maintain platform stability and performance and to reduce the risk of service disruptions caused by excessive log volume.
- Administrator access to VMware ESXi environments through the vSphere Client or ESXi Host Client
- Network connectivity between VMware systems and the vLC
Configure the ESXi Host Client
Note: Repeat these steps for each ESXi host.
- Sign in to the ESXi Host Client with administrator permissions, using the URL format
https://esxi_host-ip/ui. - Navigate to .
- Search for Syslog.global.logHost.
- Set the value to the vLC destination using the format
udp://vlc-ip:514. - Search for Syslog.global.logLevel.
- Set the logging level to info.
- Save the changes.