NSX Distributed firewall logs are not ingested in VMware Aria Operations for Log
search cancel

NSX Distributed firewall logs are not ingested in VMware Aria Operations for Log

book

Article ID: 413418

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Environment

VMware Aria Operations for Logs 8.18.x

VMware NSX 4.x

Cause

Logging is disabled by default for Distributed Firewall

Resolution

Enable logging for firewall rules on NSX Manager:

  1. Log in to the NSX Manager: Access the web interface of your NSX Manager.
  2. Navigate to Policy Management: Go to Security > Policy Management > Distributed Firewall.
  3. Locate your Firewall Rule: Find the specific rule within your Distributed Firewall policy that you want to enable logging for.
  4. Edit the Rule: Click the gear icon (settings) on the right side of the rule's row.
  5. Enable Logging: In the rule's settings, toggle the logging option to "Enable".
  6. Apply Changes: Click "Apply" to save the changes to the rule.

Note: It is recommended to enable logging for specific rules that you wish to monitor in VMware Aria Operations for Logs as it can impact the performance on the ESXi host

Additional Information

Additional documentation found here: Common Admin- Add a Distributed Firewall