<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting syslog events from VMware ESXi: I don't see all events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/590817#M103489</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/55302"&gt;@TheExpert&lt;/a&gt;,&lt;BR /&gt;Have you solved your issue? If not, what are you local inputs.conf,&amp;nbsp; props.conf and transforms.conf?&lt;/P&gt;</description>
    <pubDate>Fri, 25 Mar 2022 08:38:25 GMT</pubDate>
    <dc:creator>justynap_ldz</dc:creator>
    <dc:date>2022-03-25T08:38:25Z</dc:date>
    <item>
      <title>Getting syslog events from VMware ESXi: Why can't I see all events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/586416#M103094</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;I want to get the syslog events of my VMware ESXi hosts&amp;nbsp;(free hypervisor) in my splunk Enterprise (free edition).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I set up the ESXi hosts and installed the "Add-on for VMware ESXi Logs" (Splunk_TA_esxilogs 4.2.1). When I do a search with the IP address of a host, I only see events with the&amp;nbsp;&lt;SPAN class=""&gt;sourcetype &lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;vmware:esxlog:Rhttpproxy". I'm not filtering the search with this sourcetype. And these events aren't the same I see in the syslog file of the ESXi hosts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;When only searching for "vmware" I see more sourcetypes:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TheExpert_0-1645710296777.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18116i2443EDADD6A9370A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TheExpert_0-1645710296777.png" alt="TheExpert_0-1645710296777.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But again, I don't see all events. The sourcetype "syslog" is binded to my Sophos UTM firewall.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class=""&gt;I want to get the events of smartd of the ESXi hosts for seeing if my SATA drives are OK. In the syslog file on the ESXi host there are events but I don't see them in splunk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Any ideas, how to see the events of the syslog file of the ESXi hosts in splunk?&lt;/P&gt;
&lt;P data-unlink="true"&gt;Thank You and kind Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 13:59:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/586416#M103094</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2022-03-25T13:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting syslog events from VMware ESXi: I don't see all events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/587597#M103212</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;in the meantime I can see lot more sourcetypes of VMware ESXi events in Splunk but I still can't find SMART information which I can see in the ESXi syslog file on the hosts itself.&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 06:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/587597#M103212</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2022-03-04T06:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting syslog events from VMware ESXi: I don't see all events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/590817#M103489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/55302"&gt;@TheExpert&lt;/a&gt;,&lt;BR /&gt;Have you solved your issue? If not, what are you local inputs.conf,&amp;nbsp; props.conf and transforms.conf?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 08:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/590817#M103489</guid>
      <dc:creator>justynap_ldz</dc:creator>
      <dc:date>2022-03-25T08:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Getting syslog events from VMware ESXi: I don't see all events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/590883#M103514</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225278"&gt;@justynap_ldz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no I wasn't able to solve it with Splunk. I never changed something in the .conf files you mentioned.&lt;/P&gt;&lt;P&gt;But I had to stop sending the syslogs of the VMware ESXi hosts to Splunk because the free amount about 500 MB per day was overloaded by the VMware log data. I also use Splunk for the logs of my Sophos UTM to have a better tool for troubleshooting firewall and proxy issues. So there's not enough free space for the VMware syslogs.&lt;/P&gt;&lt;P&gt;And i found an alternative way by using VMware PowerCLI to get the SMART data from the ESXi hosts. With a PowerShell script I can read all SMART data and send a warning mail when there are issues. Í even can read data that isn't shown in the syslog of the ESXi hosts.&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 15:41:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-syslog-events-from-VMware-ESXi-Why-can-t-I-see-all/m-p/590883#M103514</guid>
      <dc:creator>TheExpert</dc:creator>
      <dc:date>2022-03-25T15:41:44Z</dc:date>
    </item>
  </channel>
</rss>

