LoFP LoFP / an administrator can reset the loghost while moving the host to a new collector. confirm that a new `--loghost` value was set in the same change and that logs are arriving at the collector.

Techniques

Sample rules

ESXi Syslog Remote Host Reset

Description

Detects the ESXi remote syslog destination being cleared with --reset=loghost. The loghost is where host logs are forwarded for retention and detection. Clearing it keeps later commands on the host only, so an external collector stops receiving them.

Detection logic

data_stream.dataset:vsphere.log and message:("syslog config set" and ("--reset loghost" or "--reset=loghost" or "reset=loghost"))