Viewing the NSX DFW log from the ESXi host console

As mentioned earlier, DFW logs are logged in a dedicated file located on the ESXi host. The DFW log filename is dfwpktlogs.log , and is located under the /var/log directory.

Log in to an ESXi host console through SSH. To view the log, use a Linux command such as more, cat, or tail against dfwpktlogs.log in the /var/log directory:

If you don't see any DFW packet logs, verify that the log settings on the DFW rule are set to Log. Otherwise, there might be no virtual machines hitting the particular DFW rule in that ESXi host.

Get VMware NSX Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.