Public-health EHR VMs need logging whenever Distributed Firewall denies traffic. What should the administrator enable?
Select an answer to reveal the explanation.
Short Explanation
If the firewall drops an EHR packet and nobody logs it, the drop never happened for the auditor. Turn logging on those deny rules and ship syslog from the hosts or Edges. vCenter events and Carbon Black alerts are not that packet log.
Full Explanation
NSX-T firewall logging is enabled per rule and exported via host or Edge syslog. That combination is what records Distributed Firewall denies on public-health EHR VMs. vCenter tasks and events do not capture NSX packet drops. Carbon Black Cloud alerts and Workspace ONE UEM compliance samples are different telemetry and do not replace DFW packet logging.