How it works...

For the DFW syslog to be active, the Log settings need to be set to Log on a per-rule basis. Starting from NSX 6.1, NSX DFW packet log messages are logged in a dedicated file in /var/log/dfwpktlogs.log on each ESXi host. The VSFWD userworld logs and VSIP kernel module logs are logged in separate files- /var/log/vsfwd.log and /var/log/vmkernel.log respectively.

Sessions are logged at the beginning and at termination for both layer- 2 and layer-3 flows. The following is a sample of the DFW packet log format:

For more information on log file entries and the possible values, refer to the NSX 6.3 logging and system events section ...

Get VMware NSX Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.