<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarding syslogs from ESX in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60012#M11879</link>
    <description>&lt;P&gt;Link updated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 00:35:05 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2017-10-16T00:35:05Z</dc:date>
    <item>
      <title>Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60006#M11873</link>
      <description>&lt;P&gt;Hi! I've followed this guide to forward syslogs from ESX 4.0 U2 (&lt;A href="http://www.splunk.com/wiki/Community:VMwareESXSyslog"&gt;http://www.splunk.com/wiki/Community:VMwareESXSyslog&lt;/A&gt;). But I'm not seeing logs appear on my Splunk server. What steps can I take to troubleshoot this? There's no firewall between the ESX hosts and the Splunk server. Splunk is running on a VM, but that shouldn't be a problem, I'm guessing?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2011 08:21:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60006#M11873</guid>
      <dc:creator>BlightMan</dc:creator>
      <dc:date>2011-08-18T08:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60007#M11874</link>
      <description>&lt;P&gt;Hi BlightMan&lt;/P&gt;

&lt;P&gt;recently I did the same, followed this &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;doc&lt;/A&gt; and it worked like a charm.&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2011 08:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60007#M11874</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2011-08-18T08:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60008#M11875</link>
      <description>&lt;P&gt;I fixed the issue. There was a typo in the Spunk Syslog Wiki - there was an extra : on the end of one of the lines. I've updated the wiki so the command is correct.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 15:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60008#M11875</guid>
      <dc:creator>BlightMan</dc:creator>
      <dc:date>2011-10-25T15:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60009#M11876</link>
      <description>&lt;P&gt;I fixed the issue. There was a typo in the Spunk Syslog Wiki - there was an extra : on the end of one of the lines. I've updated the wiki so the command is correct.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 15:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60009#M11876</guid>
      <dc:creator>BlightMan</dc:creator>
      <dc:date>2011-10-25T15:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60010#M11877</link>
      <description>&lt;P&gt;Hi @MuS,&lt;/P&gt;

&lt;P&gt;that link takes to the splunk documentation page.&lt;/P&gt;

&lt;P&gt;Can you please post the updated link ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Deven&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 00:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60010#M11877</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-16T00:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60011#M11878</link>
      <description>&lt;P&gt;Hi @BlightMan,&lt;/P&gt;

&lt;P&gt;This extra ":" you mentioned, was it under the "Set the timezone" section of that page &lt;A href="http://wiki.splunk.com/Community:VMwareESXSyslog"&gt;http://wiki.splunk.com/Community:VMwareESXSyslog&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 00:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60011#M11878</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-16T00:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60012#M11879</link>
      <description>&lt;P&gt;Link updated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 00:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60012#M11879</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-10-16T00:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60013#M11880</link>
      <description>&lt;P&gt;Thanks! @MuS&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 05:05:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60013#M11880</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-16T05:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60014#M11881</link>
      <description>&lt;P&gt;Hi @MuS,&lt;/P&gt;

&lt;P&gt;I have to set the timezone as stated in the &lt;A href="http://wiki.splunk.com/Community:VMwareESXSyslog"&gt;http://wiki.splunk.com/Community:VMwareESXSyslog&lt;/A&gt; doc by using below syntax, &lt;BR /&gt;
[host::myesx.splunk.com]&lt;BR /&gt;
TZ=UTC&lt;/P&gt;

&lt;P&gt;if I have 8 hosts that are named such as, &lt;BR /&gt;
cd.esx1.mail.....cd.esx6.mail and cd.svm1.mail...cd.svm3.mail&lt;/P&gt;

&lt;P&gt;Can I use the below syntax ?&lt;BR /&gt;
[host::cd.esx*]&lt;BR /&gt;
TZ=UTC&lt;/P&gt;

&lt;P&gt;[host::cd.svm*]&lt;BR /&gt;
TZ=UTC&lt;/P&gt;

&lt;P&gt;If not, could you please suggest me the most correct way to use the above syntax ?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 07:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60014#M11881</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2017-10-16T07:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding syslogs from ESX</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60015#M11882</link>
      <description>&lt;P&gt;I haven't done it on host yet. Usually I use sourcetype to do such things - so I cannot not really tell if this will work or not sorry ....&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 20:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-syslogs-from-ESX/m-p/60015#M11882</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-10-16T20:21:06Z</dc:date>
    </item>
  </channel>
</rss>

