Skip to main content

How to integrate your ESXi hosts

This guide will run you through how to get your ESXI hosts logging to Defense.com's SIEM platform.

Written by Alan Butcher
Updated yesterday

This integration is available on our Advanced and Enterprise packages.

Before you get started

Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.

To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.

If you already have a log collector deployed, please follow the steps outlined below.

Configuring your ESXi host

  1. Log in to your VMware vSphere Client and select your ESXi host.

  2. Navigate to the Configure tab.

  3. Under System, click on Advanced System Settings.

  4. Click Edit to change settings.

  5. Filter for: Syslog.global.logHost.

  6. Enter your collector details in the following format, replacing collector_ip_address with your collector's private IP address udp://collector_ip_address:5514

  7. Click OK to save the changes.

Allowing syslog traffic through the firewall

  1. Under the Configure tab, go to Networking > Firewall > Outgoing connections.

  2. Click EDIT.

  3. Filter for syslog.

  4. Click on the Allow connections from any IP address Checkbox and click OK.

  5. You'll now see syslog under the Outgoing tab.

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated your ESXi hosts πŸŽ‰.

Did this answer your question?