Configure to send logs to Arctic Wolf
You can configure to forward syslog data to Arctic Wolf® for security monitoring.
These resources are required:
- An activated and dedicated Collecteur de journaux virtuel (vLC)
Note: Due to the high event volume observed during Early Access (EA) customer deployments, this integration requires a dedicated vLC to help maintain platform stability and performance and to reduce the risk of service disruptions caused by excessive log volume.
- Administrative access to and the
- Network connectivity between systems and the vLC
Configure logging levels in the vSphere Client
- Sign in to the using the format
https://vsphere_server/ui. - Select the primary .
- Navigate to .
- Under Logging Settings, set the Log Level to Info.
- Click Save.
Configure syslog forwarding in the vCenter Server Management Interface (VAMI)
- Sign in as an administrator to the , using the format
https://vcenter_ip:5480. - Navigate to .
- Click Edit.
- In the Server Address field, enter the IP address of the vLC.
- In the Port field, enter 514.
- Save the configuration.