"esx.problem.vmsyslogd.auditrecord.local.disabled - The local storage of audit records is disabled due to the error", ESXi shows auditing disabled events after upgrading to 8.0 U3e
search cancel

"esx.problem.vmsyslogd.auditrecord.local.disabled - The local storage of audit records is disabled due to the error", ESXi shows auditing disabled events after upgrading to 8.0 U3e

book

Article ID: 386607

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

  • After upgrading ESXi to 8.0 U3e, following events are logged by the ESXi host

    Hostd[2098678]: [Originator@6876 sub=Vimsvc.ha-eventmgr] Event 125 : The local storage of audit records is disabled due to the error: Files are missing from the audit record storage directory. Please refer to KB-386607 for remediation steps.
  • Executing the command "esxcli system auditrecords get" shows "Audit Record Storage Active" as "False" and the value was "True" before upgrading the ESXi host.

    [root@:~]  esxcli system auditrecords get
       Audit Record Remote Transmission Active: false
       Audit Record Storage Active: false
       Audit Record Storage Capacity: 10
       Audit Record Storage Directory: /scratch/auditLog

Environment

VMware vSphere ESXi 8.0 U3e and above versions

Cause

The vSphere error is observed because initialization of audit recording to local storage has failed. This could be due to following reasons:

  1. Scratch was reconfigured while audit recording to local storage was enabled on a scratch location. In this case, initialization of audit recording fails as audit files are not found on the new scratch location.
  2. I/O error while accessing the configured audit record storage directory.

Resolution

Validate the new scratch and enable audit recording if it is due to scratch reconfiguration. New audit files will be created in the configured audit record storage directory under new scratch and old audit records can be found in the previously configured scratch path. Otherwise, please check that configured audit log directory is accessible and writable.