You can view all inbound activity to a server by desktop pool, security group, or AD group.

View inbound activity
server

You can either do a quick query using the default search criteria by clicking Search, or tailor the query according to your requirements.

Either vShield Endpoint must be installed in your environment or a domain must be registered with NSX Manager. For information on Endpoint installation, see NSX Installation and Upgrade Guide. For information on domain registration, see Register a Windows Domain with NSX Manager.

Data collection must be enabled on one or more virtual machines.

1

Log in to the vSphere Web Client.

2

Click Networking & Security and then Activity Monitoring.

3

Click the Inbound Activity tab.

4

Click the link next to Originating from.

5

Select the type of user group that you want to view activity for.

6

In Filter type, select one or more group and click OK.

7

In Where destination virtual machine, select includes or excludes to indicate whether the selected virtual machines should be included in or excluded from the search.

8

Click the link next to And where destination virtual machine.

9

Select one or more virtual machine and click OK.

10

In And where destination application, select includes or excludes to indicate whether the selected applications should be included in or excluded from the search.

11

Click the link next to And where destination application.

12

Select one or more application and click OK.

13

Click the During period (During Period icon) icon and select the time period for the search.

14

Click Search.

Search results filtered by the specified criterion are displayed. Click anywhere in the results table to view information about the users that accessed the specified virtual machines and applications.

You can export a specific record or all records on this page and save them to a directory in a .csv format by clicking the export icon on the bottom right side of the page.