5.1

Table Of Contents
vShield Endpoint Events and Alarms 14
vShield Endpoint offloads antivirus and anti-malware agent processing to a dedicated secure virtual appliance
delivered by VMware partners. Since the secure virtual appliance (unlike a guest virtual machine) doesn't go
offline, it can continuously update antivirus signatures thereby giving uninterrupted protection to the virtual
machines on the host. Also, new virtual machines (or existing virtual machines that went offline) are
immediately protected with the most current antivirus signatures when they come online.
vShield Endpoint health status is conveyed by using alarms that show in red on the vCenter Server console.
In addition, more status information can be gathered by looking at the event logs.
IMPORTANT Your vCenter Server must be correctly configured for vShield Endpoint security:
n
Not all guest operating systems are supported by vShield Endpoint. Virtual machines with non-supported
operating systems are not protected by the security solution. For information on the supported operating
systems, see the Installing vShield Endpoint section in the vShield Quick Start Guide.
n
All hosts in a resource pool containing protected virtual machines must be prepared for vShield Endpoint
so that virtual machines continue to be protected as they are vMotioned from one ESX host to another
within the resource pool.
This chapter includes the following topics:
n
“View vShield Endpoint Status,” on page 173
n
“vShield Endpoint Alarms,” on page 174
n
“vShield Endpoint Events,” on page 174
n
“vShield Endpoint Audit Messages,” on page 175
View vShield Endpoint Status
Monitoring a vShield Endpoint instance involves checking for status coming from the vShield Endpoint
components: the security virtual machine (SVM), the ESX host-resident vShield Endpoint module, and the
protected virtual machine-resident thin agent.
Procedure
1 In the vSphere Client, go to Inventory > Hosts and Clusters.
2 Select a datacenter, cluster, or ESX host resource from the resource tree.
3 Click the vShield tab.
VMware, Inc.
173