For the DFW syslog to be active, the Log settings need to be set to Log on a per-rule basis. Starting from NSX 6.1, NSX DFW packet log messages are logged in a dedicated file in /var/log/dfwpktlogs.log on each ESXi host. The VSFWD userworld logs and VSIP kernel module logs are logged in separate files- /var/log/vsfwd.log and /var/log/vmkernel.log respectively.
Sessions are logged at the beginning and at termination for both layer- 2 and layer-3 flows. The following is a sample of the DFW packet log format:
For more information on log file entries and the possible values, refer to the NSX 6.3 logging and system events section ...