<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to see vmware esxi syslog in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470046#M80830</link>
    <description>&lt;P&gt;Setup: &lt;BR /&gt;
Vmware server name - vmware_esxi01&lt;BR /&gt;
Heavy Forwarder - bos-syslog01&lt;BR /&gt;
In vmware server -&amp;gt; config -&amp;gt; Advance system settings -&amp;gt; syslog.global.loghost=tcp://bos-syslog01.acadian-asset.com&lt;/P&gt;

&lt;P&gt;And followed "Configure ESXi hosts using the vSphere Client" section of below document &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts"&gt;https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Sat, 11 Apr 2020 06:47:03 GMT</pubDate>
    <dc:creator>meenakande</dc:creator>
    <dc:date>2020-04-11T06:47:03Z</dc:date>
    <item>
      <title>Unable to see vmware esxi syslog in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470043#M80827</link>
      <description>&lt;P&gt;we are forwarding vmware esxi  syslog to splunk by using heavy forwarder. we have not installed any universal forwarder in our esxi servers.&lt;BR /&gt;
In splunk we have created a index(vmware_log) and created a token for index. but still we are not able to see logs in splunk cloud?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 13:36:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470043#M80827</guid>
      <dc:creator>meenakande</dc:creator>
      <dc:date>2020-04-08T13:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see vmware esxi syslog in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470044#M80828</link>
      <description>&lt;P&gt;Hello @meenakande ,&lt;/P&gt;

&lt;P&gt;please explain your setup and post your configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 04:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470044#M80828</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-09T04:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see vmware esxi syslog in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470045#M80829</link>
      <description>&lt;P&gt;How did you expect to get the logs?  Is the HF executing some kind of script or pull?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 23:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470045#M80829</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-04-10T23:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see vmware esxi syslog in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470046#M80830</link>
      <description>&lt;P&gt;Setup: &lt;BR /&gt;
Vmware server name - vmware_esxi01&lt;BR /&gt;
Heavy Forwarder - bos-syslog01&lt;BR /&gt;
In vmware server -&amp;gt; config -&amp;gt; Advance system settings -&amp;gt; syslog.global.loghost=tcp://bos-syslog01.acadian-asset.com&lt;/P&gt;

&lt;P&gt;And followed "Configure ESXi hosts using the vSphere Client" section of below document &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts"&gt;https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 11 Apr 2020 06:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470046#M80830</guid>
      <dc:creator>meenakande</dc:creator>
      <dc:date>2020-04-11T06:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see vmware esxi syslog in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470047#M80831</link>
      <description>&lt;P&gt;have you specified the port?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;syslog.global.loghost=tcp://bos-syslog01.acadian-asset.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;after that follow this article to check if the packets are sent:  &lt;A href="https://kb.vmware.com/s/article/1031186"&gt;https://kb.vmware.com/s/article/1031186&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;for example capture 10 packets on the interface vmk0 on the port 1514 and show the payload:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tcpdump-uw -i vmk0 -A -c 10 port 1514
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Apr 2020 18:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-see-vmware-esxi-syslog-in-splunk/m-p/470047#M80831</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-14T18:28:06Z</dc:date>
    </item>
  </channel>
</rss>

