how to configure vmware esxi host to send logs to ibm qradar

3k Views Asked by At

I have qradar setup on one host and vmware vsphere cloud setup on another host. My Vsphere cloud setup has one esxi host I want to send logs from of this esxi host to my qradar. How to do it.Please help.

2

There are 2 best solutions below

0
Lalit Garghate On
  1. Go to vSphere Web Client
  2. Click on Esxi host that you want to send logs to qradar
  3. Go to Configure -> Advance System Setting
  4. Click edit and filter keyword 'Syslog.global.logHost'
  5. put value as 'udp://:514' in 'Syslog.global.logHost' field.Click OK.
  6. Go to Configure -> Firewall
  7. Click edit and filter keyword 'syslog'
  8. Checked the syslog check box.Click OK.
0
yamin On

I want to add information on point 8, the firewall menu can be accessed via the network tab to restrict access through the firewall