You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于将ESXi或vCenter审计日志发送至HTTP端点的技术咨询

将ESXi或vCenter审计日志发送至HTTP端点的技术咨询

Hey there! Great question—this is a common ask since syslog is VMware’s default log delivery method, but sending audit logs to an HTTP/webhook endpoint is totally doable with a few workarounds (since there’s no native "direct HTTP send" option right now). Let’s break down the practical, actionable ways to make this happen:

方法1:vCenter告警动作 + PowerCLI 脚本触发

vCenter lets you trigger custom actions when specific audit events occur, and you can hook a PowerCLI script into that workflow to push logs to your HTTP endpoint. Here’s how to set it up:

  • First, create an alarm in vCenter that targets audit log events: filter by event types like AuditEvent, or narrow it to specific actions (e.g., user logins, cluster configuration changes).
  • For the alarm’s action, select "Run a script" and link to a PowerCLI script that grabs event details and sends an HTTP POST request. A quick example snippet for the script:
    # Fetch the most recent triggered audit event details
    $latestAuditEvent = Get-VIEvent -EventTypeId "AuditEvent" -MaxSamples 1 | Select-Object FullFormattedMessage, CreatedTime, UserName
    # Format payload and send to your HTTP endpoint
    $payload = @{
        timestamp = $latestAuditEvent.CreatedTime
        user = $latestAuditEvent.UserName
        log_message = $latestAuditEvent.FullFormattedMessage
    } | ConvertTo-Json
    Invoke-RestMethod -Uri "https://your-webhook-endpoint.com/audit-logs" -Method Post -Body $payload -ContentType "application/json"
    
  • Note: Make sure the vCenter server has PowerCLI installed, has network access to your HTTP endpoint, and the service account running the script has proper permissions to read vCenter events.

方法2:借助VMware Log Insight(已部署的情况下)

If you’re already using VMware Log Insight for log aggregation, it has built-in webhook support that simplifies this process:

  • First, set up Log Insight to collect audit logs from your ESXi hosts and vCenter (this is a standard setup—just add your VMware assets as log sources).
  • Create a filter in Log Insight to target only audit events (use filters like event_type:audit or more specific terms tied to your needs).
  • Set up a notification rule that triggers when this filter matches, then select "Webhook" as the notification type. Enter your HTTP endpoint URL, customize the payload format (you can use JSON templates to include all relevant log fields), and save the rule. Log Insight will automatically forward matching audit logs to your endpoint.

方法3:自定义中间件(Syslog转HTTP)

If you don’t want to use vCenter alarms or Log Insight, you can set up a lightweight intermediate server to bridge syslog and HTTP:

  • Configure ESXi/vCenter to send audit logs to this intermediate server (standard syslog setup—no changes needed on the VMware side).
  • Use tools like rsyslog or syslog-ng to receive the syslog traffic and forward it to your HTTP endpoint. Here’s a simple rsyslog config snippet to handle this:
    # Load the HTTP output module
    module(load="omhttp")
    # Define a JSON template for the payload
    template(name="audit-log-json" type="list") {
        constant(value="{")
        constant(value="\"timestamp\":\"") property(name="timereported" dateFormat="rfc3339")
        constant(value="\",\"source_host\":\"") property(name="hostname")
        constant(value="\",\"log_content\":\"") property(name="msg")
        constant(value="\"}")
    }
    # Forward only VMware audit logs to your HTTP endpoint
    if $programname == "vmware-audit" then {
        action(type="omhttp" server="your-webhook-endpoint.com" serverport="443" usehttps="on" uri="/receive-logs" template="audit-log-json")
    }
    

备注:内容来源于stack exchange,提问作者milner236

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 07:49:39