关于将ESXi或vCenter审计日志发送至HTTP端点的技术咨询
Hey there! Great question—this is a common ask since syslog is VMware’s default log delivery method, but sending audit logs to an HTTP/webhook endpoint is totally doable with a few workarounds (since there’s no native "direct HTTP send" option right now). Let’s break down the practical, actionable ways to make this happen:
方法1:vCenter告警动作 + PowerCLI 脚本触发
vCenter lets you trigger custom actions when specific audit events occur, and you can hook a PowerCLI script into that workflow to push logs to your HTTP endpoint. Here’s how to set it up:
- First, create an alarm in vCenter that targets audit log events: filter by event types like
AuditEvent, or narrow it to specific actions (e.g., user logins, cluster configuration changes). - For the alarm’s action, select "Run a script" and link to a PowerCLI script that grabs event details and sends an HTTP POST request. A quick example snippet for the script:
# Fetch the most recent triggered audit event details $latestAuditEvent = Get-VIEvent -EventTypeId "AuditEvent" -MaxSamples 1 | Select-Object FullFormattedMessage, CreatedTime, UserName # Format payload and send to your HTTP endpoint $payload = @{ timestamp = $latestAuditEvent.CreatedTime user = $latestAuditEvent.UserName log_message = $latestAuditEvent.FullFormattedMessage } | ConvertTo-Json Invoke-RestMethod -Uri "https://your-webhook-endpoint.com/audit-logs" -Method Post -Body $payload -ContentType "application/json" - Note: Make sure the vCenter server has PowerCLI installed, has network access to your HTTP endpoint, and the service account running the script has proper permissions to read vCenter events.
方法2:借助VMware Log Insight(已部署的情况下)
If you’re already using VMware Log Insight for log aggregation, it has built-in webhook support that simplifies this process:
- First, set up Log Insight to collect audit logs from your ESXi hosts and vCenter (this is a standard setup—just add your VMware assets as log sources).
- Create a filter in Log Insight to target only audit events (use filters like
event_type:auditor more specific terms tied to your needs). - Set up a notification rule that triggers when this filter matches, then select "Webhook" as the notification type. Enter your HTTP endpoint URL, customize the payload format (you can use JSON templates to include all relevant log fields), and save the rule. Log Insight will automatically forward matching audit logs to your endpoint.
方法3:自定义中间件(Syslog转HTTP)
If you don’t want to use vCenter alarms or Log Insight, you can set up a lightweight intermediate server to bridge syslog and HTTP:
- Configure ESXi/vCenter to send audit logs to this intermediate server (standard syslog setup—no changes needed on the VMware side).
- Use tools like
rsyslogorsyslog-ngto receive the syslog traffic and forward it to your HTTP endpoint. Here’s a simplersyslogconfig snippet to handle this:# Load the HTTP output module module(load="omhttp") # Define a JSON template for the payload template(name="audit-log-json" type="list") { constant(value="{") constant(value="\"timestamp\":\"") property(name="timereported" dateFormat="rfc3339") constant(value="\",\"source_host\":\"") property(name="hostname") constant(value="\",\"log_content\":\"") property(name="msg") constant(value="\"}") } # Forward only VMware audit logs to your HTTP endpoint if $programname == "vmware-audit" then { action(type="omhttp" server="your-webhook-endpoint.com" serverport="443" usehttps="on" uri="/receive-logs" template="audit-log-json") }
备注:内容来源于stack exchange,提问作者milner236

