VMware Cloud Community
TheVMinator
Expert
Expert

Host-Specific Security Events

If I have syslog data from my ESXi hosts going to a SIEM, do I also need ESXi host events?  For example, some SIEM solutions are capable of both ingesting Syslog info from an individual ESXi host, but also connecting to the host via the ESXi API, and pulling event information such as you would see in vSphere Client.  The vSphere client information is more meaningful and easier to report on in your SIEM.  However, if you are pulling event data anyway from the vCenter API, and from ESXi syslogs, do you need to also get data from individual ESXI hosts' APIs? 

0 Kudos
1 Reply
TheVMinator
Expert
Expert

anyone?

0 Kudos