Why You Shouldn’t Store Logs Locally on ESXi
By default, VMware ESXi writes service logs (vmkernel, hostd, vpxa, auth.log) to a ramdisk or a Scratch directory on the local disk. This partition typically only has a few hundred megabytes of capacity. When a host experiences a power loss, hardware failure, or a Purple Screen of Death (PSOD), all volatile logs stored in RAM vanish immediately upon reboot.
Losing log data means losing the audit trail needed for Root Cause Analysis (RCA). Furthermore, if you manage a cluster of 8–10 or more hosts, SSHing into each individual machine to inspect logs is extremely time-consuming. Centralizing logs via Remote Syslog not only enables early incident detection but also satisfies security compliance standards such as PCI-DSS or ISO 27001.
The forwarded data can be sent to whichever receiver you use: Graylog, ELK Stack, Splunk, Rsyslog, or VMware Aria Operations for Logs.
Prerequisites and Required Information
You should gather the following basic network details for your log receiver before proceeding:
- Syslog Server: Static IP address or FQDN of the log collection server (e.g.,
192.168.10.50orsyslog.itfromzero.local). - Protocol & Port:
UDP:514: Fast and lightweight, but prone to packet loss during network congestion or log spikes.TCP:514: Guarantees no log loss; recommended for production environments.SSL/TLS:1514: Encrypted transport, suitable when sending logs across high-security subnets.
- Access Permissions: Root credentials (SSH) or Administrator privileges on vSphere Client / Host Client.
Method 1: Configure via esxcli Command Line (Fastest & Most Accurate)
The CLI is the ideal choice when automating configuration across multiple hosts via scripts or an SSH session. Enable SSH on ESXi and execute the following four steps in order:
Step 1: View Current Syslog Configuration
esxcli system syslog config get
This command returns the operational status, local storage path, and the current destination for the Remote Host field.
Step 2: Assign Syslog Server Address
Use the esxcli system syslog config set command with the --loghost parameter. The standard syntax is protocol://host:port:
# Forward logs over TCP port 514 (recommended to prevent log loss)
esxcli system syslog config set --loghost='tcp://192.168.10.50:514'
# Forward logs over UDP port 514
esxcli system syslog config set --loghost='udp://192.168.10.50:514'
# Forward simultaneously to 2 servers (primary and backup)
esxcli system syslog config set --loghost='tcp://192.168.10.50:514,tcp://192.168.10.51:514'
Step 3: Reload the Syslog Service
Apply the new configuration immediately without rebooting the host:
esxcli system syslog reload
Step 4: Open ESXi Firewall for Syslog Traffic
ESXi includes a built-in firewall that blocks all outbound traffic by default. You need to enable the rule for syslog:
# Enable the outbound rule for syslog
esxcli network firewall ruleset set --ruleset-id=syslog --enabled=true
# Reload the firewall to apply the new rule
esxcli network firewall refresh
Method 2: Configure via ESXi Host Client (Web GUI)
If you prefer using a web interface over the terminal, you can easily configure it using the GUI:
- Access the ESXi Host Client via
https://<IP-ESXi>/ui. - Navigate to Manage > select the System tab > choose Advanced settings.
- Search for the key
Syslog.global.logHostusing the filter box in the upper-right corner. - Right-click the entry, select Edit option, enter the value (e.g.,
tcp://192.168.10.50:514), and click Save. - Go to Networking > Firewall rules tab > find the syslog rule, right-click, and select Enable.
Testing and Verifying Log Flow
Once configured, verify whether log messages are reaching their destination.
1. Send a Test Log from ESXi
Run the logger command directly in the ESXi Shell to generate a test event:
logger -p user.info "ESXI_SYSLOG_TEST: Successfully sent from host esxi-01 to central syslog server"
2. Check Logs on the Receiving Server
If using Rsyslog on Ubuntu Server, open a terminal on the receiver and filter for the test message:
tail -f /var/log/syslog | grep ESXI_SYSLOG_TEST
# Or check a dedicated file if you have configured per-host log segregation
tail -f /var/log/remote-hosts/esxi-01.log
If the terminal outputs the test string along with the ESXi IP/hostname, your log forwarding pipeline is working smoothly.
Common Issues and Quick Fixes
- Logs not appearing on the server: Verify that port 514 on the log server is in a LISTEN state (
ss -tuln | grep 514). Also ensure the server’s local firewall (UFW or Firewalld) is not blocking inbound traffic on this port. - DNS Resolution Errors: When specifying loghost with a domain name (e.g.,
syslog.corp.net), ensure ESXi is configured with the correct DNS servers (check withesxcli network ip dns server list). Within local networks, using a static IP is always the most stable option. - Log Loss Under High Load: In clusters running 50–100 VMs, log volume can reach thousands of lines per second. UDP is prone to dropping packets under these conditions. Switch to
tcp://to ensure no log entries are missed.

