VMware ESXi (Preview) connector for Sentinel not connected

Kibalatu 21 Reputation points
2022-06-28T19:20:10.557+00:00

I having problems getting the VMware ESXi (Preview) connector to get connected from Sentinel. From VMware side it seems to be working because I can see the logs getting into the Syslog Linux(Ubuntu)Agent. But From Sentinel the connector shows not connected, I have created the and saved the parse function but still not connected. Below are some of the logs from the ESXi host to the syslog agent. Any help will be appreciated.

Jun 28 18:40:58 MX01-S3.bcfs.local vsansystem: info vsansystem[2102858] [vSAN@6876 sub=Libs] VsanInfoImpl: Refresh config generation
Jun 28 18:40:58 MX01-S3.bcfs.local vsansystem: info vsansystem[2102858] [vSAN@6876 sub=Libs] VsanInfoImpl: vSan mode is set to : Mode_None
Jun 28 18:40:58 MX01-S3.bcfs.local vsansystem: info vsansystem[2102858] [vSAN@6876 sub=Libs] VsanInfoImpl: Loading 0 dit subclusters from config store on normal node
Jun 28 18:40:58 MX01-S3.bcfs.local vsansystem: info vsansystem[2102858] [vSAN@6876 sub=Libs] VsanInfoImpl: Assigning the default datastore
Jun 28 18:40:58 MX01-S3.bcfs.local VSANMGMTSVC: error vsand[2102858] [opID=MainThread VsanHostHelper::isWitnessHost] vsi.get /vmkModules/vsanutil/isWitness exception b ecasue of Bad parameter.

Azure VMware Solution
Azure VMware Solution
An Azure service that runs native VMware workloads on Azure.
393 questions
Microsoft Security | Microsoft Sentinel
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.