<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding ESX hosts to an existing Splunk server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85632#M17797</link>
    <description>&lt;P&gt;I've just checked on a couple of ESX hosts that the splunk server is collecting log information from and did a global find for both outputs.conf and inputs.conf, nothing was returned. What is the default location for the splunk forwarders on a ESX node ?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2012 14:57:59 GMT</pubDate>
    <dc:creator>mikeyw</dc:creator>
    <dc:date>2012-10-10T14:57:59Z</dc:date>
    <item>
      <title>Adding ESX hosts to an existing Splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85630#M17795</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've inherited a splunk server that was setup to receive to vmkwarning files from around 20 ESX hosts.&lt;/P&gt;

&lt;P&gt;Recently i built another 5 hosts running ESX5 that i'd like to also get the vmkwarning files sent to the splunk server, what's the best guide to show me how to do this ?&lt;/P&gt;

&lt;P&gt;I presume some kind of splunk forwarding agent has to reside on the ESX host ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 09:30:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85630#M17795</guid>
      <dc:creator>mikeyw</dc:creator>
      <dc:date>2012-10-10T09:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ESX hosts to an existing Splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85631#M17796</link>
      <description>&lt;P&gt;Yes, you'll need to install a splunk forwarder on the ESX host.  Then you'll set up file monitoring.  Take a look at one of your existing ESX server forwarders. You should find settings in &lt;SPLUNK_HOME&gt;/etc/system/local/  in outputs.conf and inputs.conf.  Outputs will have the settings for communicating back to the Splunk server and inputs.conf has the details of the file being monitored.  In this case probably /var/log/vmkwarning.log.&lt;/SPLUNK_HOME&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Deploymentoverview"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Deploymentoverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 12:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85631#M17796</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-10T12:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ESX hosts to an existing Splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85632#M17797</link>
      <description>&lt;P&gt;I've just checked on a couple of ESX hosts that the splunk server is collecting log information from and did a global find for both outputs.conf and inputs.conf, nothing was returned. What is the default location for the splunk forwarders on a ESX node ?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 14:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85632#M17797</guid>
      <dc:creator>mikeyw</dc:creator>
      <dc:date>2012-10-10T14:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Adding ESX hosts to an existing Splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85633#M17798</link>
      <description>&lt;P&gt;Any further thoughts here guys ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 08:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-ESX-hosts-to-an-existing-Splunk-server/m-p/85633#M17798</guid>
      <dc:creator>mikeyw</dc:creator>
      <dc:date>2012-10-11T08:53:33Z</dc:date>
    </item>
  </channel>
</rss>

