3.1 Ensure a centralized location is configured to collect ESXi host core dumps

Information

The VMware vSphere Network Dump Collector service allows for collecting diagnostic
information from a host that experiences a critical fault. This service provides a centralized
location for collecting ESXi host core dumps.

*Rationale*

When a host crashes, an analysis of the resultant core dump is essential to being able to
identify the cause of the crash to identify a resolution. Installing a centralized dump
collector helps ensure that core files are successfully saved and made available in the event
an ESXi host should ever panic.

Solution

To implement the recommended configuration state, run the following ESXi shell
command-# Configure remote Dump Collector Server
esxcli system coredump network set -v [VMK#] -i [DUMP_SERVER] -o [PORT]
# Enable remote Dump Collector
esxcli system coredump network set -e true

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-9(2), CSCv7|6.5

Plugin: Unix

Control ID: 51aa39f8177842c6a78a6ac1c1116d1b73990514c46492ee70d7bfcad6b67ef1