Techniques
Sample rules
ESXi Syslog Remote Host Reset
- source: elastic
- technicques:
- T1562
Description
Detects the ESXi remote syslog destination being cleared with --reset=loghost. The loghost is where host logs
are forwarded for retention and detection. Clearing it keeps later commands on the host only, so an external
collector stops receiving them.
Detection logic
data_stream.dataset:vsphere.log and message:("syslog config set" and ("--reset loghost" or "--reset=loghost" or "reset=loghost"))