Answer the question
In order to leave comments, you need to log in
Detailed VMware ESXi logs (usernames generating events)?
I process the logs transmitted by the ESXi server to the syslog server.
Faced the problem that all data that is transmitted is anonymized. It is pointless to have information that a virtual machine has been changed/deleted/created without the initiator of the change.
After analyzing directly on the server in the \var\log directory, I came to the conclusion that usernames are missing even at the highest level of logs (trivia).
Tell me, in which direction to dig?
Answer the question
In order to leave comments, you need to log in
Why give anyone access to esxi at all?
If there is no vcenter there, I
recently sat with esxi logs and my inner instinct tells me that there is no way.
A good and quite normal practice is access to ESXi by one or two admins + a piece of paper with a password in the boss's safe.
the rest - only to virtual machines, or to a specific virtual machine
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question