vCenter makes most of it's logging available in the Windows Event log for software-based installations, and via Syslog for appliance (VCSA) installations, at least from version 6 onward.

Since Sentinel can handle these logs using native interfaces (SAM, WECS, Syslog connector) Sentinel should pull these logs in.

Comments

  • So a parser development is needed?