Configuring VMware Syslogs

To monitor with full accountability, your VMware devices must send syslogs to SecureTrack. To do this, define SecureTrack as a syslog server for each monitored VMware device.

Syslog traffic must be configured to arrive to the SecureTrack server that monitors the device (Central Server, Distribution Server or Remote Collector Server) from the IP and/or host name of the device.

For more information see Sending Additional Information via Syslog.

Syslog proxy is supported for specific devices. For more information on syslog proxy support for supported devices, see Configuring Devices to Send Logs.

Only rules that are marked for logging in the device are included in the syslogs. For NSX-T devices that work with declarative APIs, real time monitoring (accountability) is supported only for syslogs which were received with the default messageid.