<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ESXI VMware Login Tracking in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339911#M62715</link>
    <description>&lt;P&gt;Here are some examples, I am finding it difficult to track logins or anything useful via these logs as well.&lt;/P&gt;

&lt;P&gt;These will not be exact as I changed some of the data to anonymise it.&lt;/P&gt;

&lt;P&gt;Web login:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T17:21:47.761+10:00 info vpxd[50692] [Originator@0000 sub=[SSO] opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) 
2017-06-28T17:21:47.824+10:00 info vpxd[50692] [Originator@0000 sub=[SSO] opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) res: DOMAIN\username 
2017-06-28T17:21:47.825+10:00 info vpxd[50692] [Originator@0000 sub=AuthorizeManager opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [Auth]: User DOMAIN\username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Failed login via website:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:12:49.076+10:00 error vpxd[53560] [Originator@0000 sub=User opID=90186654-00000004-ac] Failed to authenticate user &amp;lt;DOMAIN\username&amp;gt;
2017-06-28T18:12:54.085+10:00 info vpxd[53560] [Originator@0000 sub=Default opID=90186654-00000004-ac] [VpxLRO] -- ERROR task-internal-196035 -- SessionManager -- vim.SessionManager.login: vim.fault.InvalidLogin: --&amp;gt; Result: --&amp;gt; (vim.fault.InvalidLogin) { --&amp;gt; faultCause = (vmodl.MethodFault) null, --&amp;gt; msg = "" --&amp;gt; } --&amp;gt; Args: --&amp;gt; --&amp;gt; Arg userName: --&amp;gt; "DOMAIN\username" --&amp;gt; Arg password: --&amp;gt; (not shown) --&amp;gt; --&amp;gt; Arg locale: --&amp;gt; "en_US"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thick client login&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:13:27.734+10:00 info vpxd[60232] [Originator@0000 sub=AuthorizeManager opID=EC8E8DD2-00000004-5f] [Auth]: User DOMAIN\username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thick client login via SSO:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:19:37.777+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) 
2017-06-28T18:19:37.865+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) res: DOMAIN\username 
2017-06-28T18:19:37.929+10:00 info vpxd[65192] [Originator@0000 sub=AuthorizeManager opID=5DFF3E13-00000005-cf] [Auth]: User DOMAIN\username
2017-06-28T18:19:37.940+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserFullName(DOMAIN\username, false) res: FirstName Lastname 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 04 Aug 2017 08:58:36 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2017-08-04T08:58:36Z</dc:date>
    <item>
      <title>ESXI VMware Login Tracking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339910#M62714</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;how can i track login and logout from ESXi 5.5?&lt;/P&gt;

&lt;P&gt;At the moment i configured a Syslog to forward logs from ESXI to splunk but the logins are not tracked.&lt;/P&gt;

&lt;P&gt;How can i solve this issue?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 12:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339910#M62714</guid>
      <dc:creator>mbarbaro</dc:creator>
      <dc:date>2017-08-01T12:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: ESXI VMware Login Tracking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339911#M62715</link>
      <description>&lt;P&gt;Here are some examples, I am finding it difficult to track logins or anything useful via these logs as well.&lt;/P&gt;

&lt;P&gt;These will not be exact as I changed some of the data to anonymise it.&lt;/P&gt;

&lt;P&gt;Web login:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T17:21:47.761+10:00 info vpxd[50692] [Originator@0000 sub=[SSO] opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) 
2017-06-28T17:21:47.824+10:00 info vpxd[50692] [Originator@0000 sub=[SSO] opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) res: DOMAIN\username 
2017-06-28T17:21:47.825+10:00 info vpxd[50692] [Originator@0000 sub=AuthorizeManager opID=c2c6af008-0000-457a-83d3-002dfe600e05-090-ngc-00] [Auth]: User DOMAIN\username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Failed login via website:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:12:49.076+10:00 error vpxd[53560] [Originator@0000 sub=User opID=90186654-00000004-ac] Failed to authenticate user &amp;lt;DOMAIN\username&amp;gt;
2017-06-28T18:12:54.085+10:00 info vpxd[53560] [Originator@0000 sub=Default opID=90186654-00000004-ac] [VpxLRO] -- ERROR task-internal-196035 -- SessionManager -- vim.SessionManager.login: vim.fault.InvalidLogin: --&amp;gt; Result: --&amp;gt; (vim.fault.InvalidLogin) { --&amp;gt; faultCause = (vmodl.MethodFault) null, --&amp;gt; msg = "" --&amp;gt; } --&amp;gt; Args: --&amp;gt; --&amp;gt; Arg userName: --&amp;gt; "DOMAIN\username" --&amp;gt; Arg password: --&amp;gt; (not shown) --&amp;gt; --&amp;gt; Arg locale: --&amp;gt; "en_US"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thick client login&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:13:27.734+10:00 info vpxd[60232] [Originator@0000 sub=AuthorizeManager opID=EC8E8DD2-00000004-5f] [Auth]: User DOMAIN\username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thick client login via SSO:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-06-28T18:19:37.777+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) 
2017-06-28T18:19:37.865+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserInfo(DOMAIN\username, false) res: DOMAIN\username 
2017-06-28T18:19:37.929+10:00 info vpxd[65192] [Originator@0000 sub=AuthorizeManager opID=5DFF3E13-00000005-cf] [Auth]: User DOMAIN\username
2017-06-28T18:19:37.940+10:00 info vpxd[65192] [Originator@0000 sub=[SSO] opID=5DFF3E13-00000005-cf] [UserDirectorySso] GetUserFullName(DOMAIN\username, false) res: FirstName Lastname 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Aug 2017 08:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339911#M62715</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-08-04T08:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: ESXI VMware Login Tracking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339912#M62716</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;thanks for the informations.&lt;/P&gt;

&lt;P&gt;I have some problem to forward logs at the moment, do you suggest something? To get this type of logs i should configure syslog-ng on the vcenter right?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 09:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339912#M62716</guid>
      <dc:creator>mbarbaro</dc:creator>
      <dc:date>2017-08-04T09:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: ESXI VMware Login Tracking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339913#M62717</link>
      <description>&lt;P&gt;The above example were mostly from the VCentre logs, esxi logs would be slightly different again.&lt;/P&gt;

&lt;P&gt;The VMWare firewall appears to allow port 514 and 1514 by default (TCP and UDP I believe) so if you are using one of those ports it should just work...&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 22:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ESXI-VMware-Login-Tracking/m-p/339913#M62717</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-08-04T22:33:17Z</dc:date>
    </item>
  </channel>
</rss>

