Configuring VMware vCenter Syslog Forwarding to Microsoft Sentinel
search cancel

Configuring VMware vCenter Syslog Forwarding to Microsoft Sentinel

book

Article ID: 444661

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native Security Information and Event Management (SIEM) and security platform. It aggregates, analyzes, and mitigates security threats across multi cloud, hybrid, and on-premises environments using AI, automation, and deep data analytics.
  • This article provides step-by-step instructions for onboarding VMware vCenter Server logs into Microsoft Sentinel. Because Microsoft Sentinel cannot directly pull logs from an on-premises vCenter network, a dedicated Linux-based Syslog Collector VM acts as an intermediary gateway utilizing the Azure Monitor Agent (AMA).

Environment

VMware vCenter server

Resolution

Configure vCenter to stream logs externally by referring Forward vCenter Server Log Files to Remote Syslog Server

  1. Log in to the vCenter Server Management Interface (https://<vcenter-ip-or-fqdn>:5480).

  2. Click on Syslog in the left navigation panel.

  3. Click Configure (or Edit if a baseline exists).

  4. Enter the destination details:

    • Server Address: <IP-of-your-Syslog-Collector-VM>

    • Protocol: UDP (or TCP depending on infrastructure preferences)

    • Port: 514

  5. Click Save. Verify that the status shifts to Running.