Configure VMware ESXi syslog forwarding using Host Profiles
You can configure VMware ESXi to forward syslog data to Arctic Wolf by applying a Host Profile cluster-wide. This method is recommended for large environments.
Note: Cluster-wide Host Profile management might require a VMware Enterprise Plus license, depending on the VMware version and licensing model.
These resources are required:
- An activated and dedicated Virtual Log Collector (vLC)
Note: Due to the high event volume observed during Early Access (EA) customer deployments, this integration requires a dedicated vLC to help maintain platform stability and performance and to reduce the risk of service disruptions caused by excessive log volume.
- Administrator access to VMware ESXi environments through the vSphere Client or ESXi Host Client
- Network connectivity between VMware systems and the vLC
Configure the reference host
Configure one reference ESXi host to be used for the Host Profile.
- Sign in to the VMware vSphere Client with administrator permissions, using the URL format
https://vsphere_server/ui. - Navigate to Hosts and Clusters.
- Select the applicable ESXi host.
- Navigate to .
- In the Key column filter, search for Syslog.global.logHost.
- Set the value to the vLC destination using the format
udp://vlc_ip:514. - In the Key column filter, search for Syslog.global.logLevel.
- Set the logging level to info.
- Save the changes.