You can use the vSphere Web Client to configure syslog on an ESXi host to forward log messages to vRealize Log Insight.

To forward log messages from multiple ESXi hosts within the vCenter Server to vRealize Log Insight, you must configure each ESXi host.


The procedure might vary depending on the version of the ESXi host that you configure, and the vSphere Web Client that you use .


If you already configured an ESXi host to forward log events to vRealize Log Insight by following the Configure an ESXi Host to Forward Log Events to vRealize Log Insight procedure, you can ignore the manual configuration procedure.

Verify that you have user credentials with enough privileges to configure syslog on ESXi hosts.

Host.Configuration.Advanced settings

Host.Configuration.Security profile and firewall


You must configure the permission on the top-level folder within the vCenter Server inventory, and verify that the Propagate to children check box is selected.

Verify that you are logged in to the vCenter Server that manages the ESXi host that you want to configure.


From the object navigator, select the ESXi host that you want to configure, and click the Manage tab.


On the Settings tab, click Advanced System Settings.


Locate the property and click the Edit icon .


Modify the property to point to the vRealize Log Insight IP address or host name and click OK.

The format is tcp|udp|ssl://log_insight-host:514|1514, where log_insight-host is the IP address or host name of the vRealize Log Insight virtual appliance.


Use port 514 for UDP and TCP communication, and port 1514 for SSL protocol.


Verify that Firewall is not blocking the communication ports.


On the Settings tab, click Security Profile, and verify that syslog appears in the Outgoing Connections list.


If you do not see syslog in the Outgoing Connections list, click Edit on the upper right.


On the list of services, scroll down to locate the syslog service, and select the syslog check box.


Click OK.