VMware NSX
VMware NSX is a platform for creating and managing virtual networks. It provides advanced security, automation, and precise network control (micro segmentation) for modern data centers and cloud systems.
This pack includes Cortex XSIAM content.
What this pack contains
- Modeling rules for VMWare NSX
- Syslog integration
Server side configuration
This section explains how to configure your VMware NSX server to forward its event logs to the Cortex XSIAM Broker VM using syslog.
From your browser, log in with admin privileges to an NSX Manager at
https://nsx-manager-ip-address
.Select, System -> Fabric -> Profiles.
Click the Node Profiles tab.
In the Name column, click All NSX Nodes.
In the Syslog Servers section, click Add to add a syslog server.
- Enter the FQDN or IP address of the syslog server.
- Specify a port number.
- Select a protocol. - The available protocols are TCP, UDP, and LI (Log Insight).
- Select a log level. The available levels are Emergency, Alert, Critical, Error, Warning, Notice, Information, and Debug.
- Click Add.
Repeat step 5 to add more syslog servers, if required.
For more information, see Add Syslog Servers for NSX Nodes
NOTE: This pack supports Syslog RFC 5424 format as shown in the following article here.
Collect events from the vendor
In order to use the collector, use the Broker VM option.
Broker VM
Configure the Broker VM as described here.
You can configure the specific vendor and product for this instance.
Navigate to Settings → Configuration → Data Broker → Broker VMs.
Right-click, and select Syslog Collector → Configure.
When configuring the syslog collector, set the following parameters:
Parameter Value Protocol
Should be aligned with the port defined in the NSX Server Management Interface syslog configuration, as described in the Server side configuration section above. Port
Should be aligned with the port defined in the NSX Server Management Interface syslog configuration, as described in the Server side configuration section above. Format
Select Auto-Detect. Vendor
Enter VMware. Product
Enter NSX.