On This Page
Configuring a VMware NSX-V Device to Send Syslogs
|
This topic is intended for TOS Administrators. |
Overview
Syslog traffic must be configured to arrive to the TOS cluster that monitors the device - see Sending Additional Information via Syslog.
Syslog proxy is supported for specific devices. For more information on syslog proxy support for supported devices, see Configuring Devices to Send Logs.
Only rules that are marked for logging in the device are included in the syslogs.
Define SecureTrack as a Syslog Server on a VMware NSX Device
-
From the vSphere Client or the vSphere Web Admin, login to either the vCenter server or directly to the relevant ESXi server.
-
Select the ESXi server and select the Configuration tab.
-
Under the Software heading, select Advanced Settings.
-
From the list of settings, select Syslog > Global.
-
In the Syslog.global.logHost field, enter the connection information for SecureTrack in the syntax:
udp://<ip_address>:514
For example:
udp://192.168.0.1:514
-
Make sure the Distributed Firewall rules are configured with the Log option. (VMware NSX documentation)
-
(Optional) To configure the NSX Manager to send change logs to SecureTrack to receive revisions when firewall rules are changed:
-
Login to the NSX Manager.
-
Click Manage Appliance Settings.
-
In the Settings > General section, in the Syslog Server section click Edit.
-
Enter the SecureTrack server details:
-
Syslog server: The appropriate TOS destination described in Sending Additional Information via Syslog.
-
Port: Enter 514.
-
Protocol: Select UDP.
Click OK.
-
-
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague