If logging is enabled for Distributed Firewall rules, the firewall packet logs will be stored at /var/log/dfwpktlogs.log on ESXi hosts.
Customer may want to modify the default Distributed Firewall Packet Log file size or rotation settings for specific purposes.
VMware NSX
The configuration file /etc/vmsyslog.conf.d/dfwpktlogs.conf on each ESXi host defines the size and rotation count settings for NSX Distributed Firewall (DFW) Packet Logs.
⚠️ Note: Modifying the default DFW Packet Log settings is generally not recommended. Always consider the available storage space on the ESXi host before increasing the log file size or rotation count.
However, if there is a valid reason to change the configuration, you can follow these steps:
Steps to Modify DFW Packet Log Settings:
1. Edit the configuration file on the ESXi host and adjust the following parameters as needed:
# Number of rotated files
rotate = 10
# Rotate size
size = 10240
Note: The size value is in kilobytes (KB). For example, 10240 KB equals 10 MB.
2.Reload the syslog service from ESXi shell to apply the changes:
esxcli system syslog reload
This configuration must be applied individually on each ESXi host.
Ensure that any custom settings comply with your log retention policies and available disk space.