Log in to the vCenter Server Appliance Management Interface as root.
Configuring VMware vCenter
To configure log forwarding to syslog follow these steps:
- In the vCenter Server Appliance Management Interface, select Syslog.
- In the Forwarding Configuration section, click Configure to add remote syslog host.
- In the Create Forwarding Configuration pane, enter the server address of the destination host. The maximum number of supported destination hosts is three. <Forwarder IP>
- From the Protocol drop-down menu, select the protocol to use
- In the Port text box, enter the port number (11724) to use for communication with the destination host
- Click Save
Once the configuration is completed, need to validate the logs in chronicle using a regular expression as (".*") this expression or with specific hostname, will provide the log source types which are ingesting to chronicle, below is the screen shot for reference.