ESXi 8.x
This behavior is typically caused by the use of the UDP protocol for syslog forwarding:
To ensure reliable and chronological log ingestion, reconfigure the ESXi hosts to use TCP or SSL/TLS for syslog forwarding.
1. Reconfigure Syslog Protocol to TCP:
esxcli system syslog config set --loghost='tcp://<syslog-server-ip>:514'esxcli system syslog reload2. Configure Syslog Parsing:
Ensure that the Syslog is configured to: