Hello;

On ESXi just forward the events via SYSLOG then capture the events with 
OSSEC.

ESXi -> Syslog <- OSSEC

Details for ESX and ESXi Syslog forward :
http://beyondvm.com/tutorial-esx-4-0-syslog-configuration

Kind regards

Reply via email to