6.5.1

Table Of Contents
Component Location Purpose
Shell log
/var/log/shell.log
Contains a record of all commands typed
into the ESXi Shell as well as shell events
(for example, when the shell was
enabled).
Authentication
/var/log/auth.log
Contains all events related to
authentication for the local system.
System messages
/var/log/syslog.log
Contains all general log messages and
can be used for troubleshooting. This
information was formerly located in the
messages log file.
Virtual machines The same directory as the affected
virtual machine's configuration files,
named vmware.log and vmware*.log. For
example, /vmfs/volumes/datastore/v
irtual machine/vwmare.log
Contains virtual machine power events,
system failure information, tools status
and activity, time sync, virtual hardware
changes, vMotion migrations, machine
clones, and so on.
Securing Fault Tolerance Logging Trac
VMware Fault Tolerance (FT) captures inputs and events that occur on a primary VM and sends them to
the secondary VM, which is running on another host.
This logging traffic between the primary and secondary VMs is unencrypted and contains guest network
and storage I/O data, as well as the memory contents of the guest operating system. This traffic might
include sensitive data such as passwords in plaintext. To avoid such data being divulged, ensure that this
network is secured, especially to avoid man-in-the-middle attacks. For example, use a private network for
FT logging traffic.
vSphere Security
VMware, Inc. 110