ESXi Host Logs Deleted with rm
Description
Detects a shell rm of a path under /var/log or of a *.log name. Those files hold shell commands,
authentication, and hostd activity. Removing them takes away the record of what changed on the host.
Query · kuery
data_stream.dataset:vsphere.log and event.module:vsphere and message:(rm and ("*.log" or "/var/log/*"))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.path
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- An administrator deletes a rotated log under `/var/log` during a documented maintenance window. Confirm the path and the change ticket.
Analyst notes
Investigating ESXi Host Logs Deleted with rm
shell.log records the typed command. The rule matches a line that contains rm together with a /var/log/ path or a *.log name, such as [root]: rm -f /var/log/hostd.log or [root]: rm *.log.
Possible investigation steps
- Read message and note the path that was deleted.
- On the host, list /var/log and see which files are missing, including shell.log, auth.log, and hostd.log.
- Review account changes, firewall changes, and VM power events from the same session that are still in the index.
False positive analysis
Deleting one rotated log during maintenance can be expected. rm *.log removes every log name in the current directory and should be explained by a ticket.
Response and remediation
- If the delete was not approved, isolate the host and preserve any remaining logs before they rotate.
- Rotate credentials used in that shell session.
- Confirm remote syslog still has a copy of the deleted host logs.