ESXi hosts or vCenter Server Appliance instances generate unstructured log data that can be analyzed in vRealize Log Insight.

About this task

You use the vRealize Log Insight Administration interface to configure ESXi hosts on a registered vCenter Server to push syslog data to vRealize Log Insight.


Running parallel configuration tasks might result in incorrect syslog settings on the target ESXi hosts. Verify that no other administrative user is configuring the ESXi hosts that you intend to configure.

A vRealize Log Insight cluster can utilize a load balancer to distribute ESXi and vCenter Server Appliance syslog feeds between the individual nodes of the cluster.

For information on filtering syslog messages on ESXi hosts before messages are sent to vRealize Log Insight, see the Configure Log Filtering on ESXi Hosts topic in the Setting Up ESXi section, of the vSphere Installation and Setup guide.

For information on configuring syslog feeds from a vCenter Server Appliance, see Configure vCenter Server to Forward Log Events to vRealize Log Insight.


vRealize Log Insight can receive syslog data from ESXi hosts version 5.0 and later.

For vSphere Web Client versions 5.0 and 5.1, logging is interrupted following a vRealize Log Insight restart, or loss in connectivity. Rerun the configuration process in these instances, to restart the logging process.


  • Verify that the vCenter Server that manages the ESXi host is registered with your vRealize Log Insight instance.

  • Verify that you have user credentials with enough privileges to configure syslog on ESXi hosts.

    • Host > Configuration > Advanced settings

    • Host > Configuration > Security profile and firewall


    You must configure the permission on the top-level folder within the vCenter Server inventory, and verify that the Propagate to children check box is selected.


  1. Click the configuration drop-down menu icon and select Administration.
  2. Under Integration, click vSphere.
  3. Locate the vCenter Server instance that manages the ESXi host from which you want to receive syslog feeds.
  4. Select the Configure ESXi hosts to send logs to Log Insight check box.

    By default, vRealize Log Insight configures all reachable ESXi hosts of version 5.0 and later to send their logs through UDP.

  5. (Optional) Enter the hostname or IP address of a load balancer you want to use to distribute syslog feeds.
  6. (Optional) To select which ESXi hosts forward their logs to vRealize Log Insight, or to select which protocol is used, click Advanced Options.
  7. Click Save.