3.4 Configure remote logging for ESXi hosts

Information

NOTE: Update LOG_HOST to the appropriate value for the local environment.

Solution

Perform the following-1. Install/Enable a syslog host (i.e vSphere Syslog Collector).
2. From the vSphere web client select the host and click 'Manage' -> 'Advanced Sytem
Settings'
3. Enter Syslog.global.logHost in the filter.
4. Set the Syslog.global.logHost to the hostname of your syslog server.To implement the recommended configuration state, run the following PowerCLI
command-# Set Syslog.global.logHost for each host
Get-VMHost | Foreach { Set-VMHostAdvancedConfiguration -VMHost $_ -Name
Syslog.global.logHost -Value '<NewLocation>' }
Note- When setting a remote log host it is also recommended to set the
'Syslog.global.logDirUnique' to true. You must configure the syslog settings for each host.
The host syslog parameters can also be configured using the vCLI or PowerCLI, or using an
API client.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2)

Plugin: VMware

Control ID: 0468527e418daf8ec32442af46e0bd80751770159f201235e1d32a577bd4f477