ESXi Audit Records Disabled
Description
Detects ESXi audit record transmission being turned off, locally or to a remote collector. Audit records are the host's own trail of administrative changes. Disabling them means later changes to accounts, the firewall, and SSH are not recorded there.
Query · kuery
data_stream.dataset:vsphere.log and message:(auditrecords and ("--enabled false" or "--enabled=false" or "local disable" or "remote disable"))
Investigation fields
Pivot points the source recommends for triage.
@timestampmessageevent.originalhost.hostnamelog.file.pathhost.ip
Implementation guide
This rule requires ESXi host logs collected by the Elastic vSphere integration: https://www.elastic.co/docs/reference/integrations/vsphere
Known false positives
- Audit settings change during collector maintenance. Confirm that transmission was enabled again and that the change matches a ticket.
Analyst notes
Investigating ESXi Audit Records Disabled
ESXi audit records capture administrative changes. Turning off local or remote transmission hides the commands that follow, including firewall, account, and VM actions.
Possible investigation steps
- Read message to see whether local or remote transmission was disabled.
- Check for a later auditrecords command that sets --enabled true.
- Correlate with syslog reset, firewall changes, and VM shutdowns.
False positive analysis
A collector outage can include a temporary disable. The setting should be turned back on in the same change.
Response and remediation
- Re-enable local and remote audit transmission.
- Review shell and hostd logs for commands issued while auditing was off.
- If the disable was unauthorized, isolate the host and rotate credentials.