<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do i forward vmware syslog to  splunk cloud without using forwarder on esxi operating system in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-forward-vmware-syslog-to-splunk-cloud-without-using/m-p/489103#M194040</link>
    <description>&lt;P&gt;We have a splunk cloud in our environment and how do i setup a vmware logs to forward to splunk cloud with out installing any Splunk universal forwarder on esxi server? &lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2020 14:59:41 GMT</pubDate>
    <dc:creator>meenakande</dc:creator>
    <dc:date>2020-03-09T14:59:41Z</dc:date>
    <item>
      <title>How do i forward vmware syslog to  splunk cloud without using forwarder on esxi operating system</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-forward-vmware-syslog-to-splunk-cloud-without-using/m-p/489103#M194040</link>
      <description>&lt;P&gt;We have a splunk cloud in our environment and how do i setup a vmware logs to forward to splunk cloud with out installing any Splunk universal forwarder on esxi server? &lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 14:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-forward-vmware-syslog-to-splunk-cloud-without-using/m-p/489103#M194040</guid>
      <dc:creator>meenakande</dc:creator>
      <dc:date>2020-03-09T14:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do i forward vmware syslog to  splunk cloud without using forwarder on esxi operating system</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-i-forward-vmware-syslog-to-splunk-cloud-without-using/m-p/489105#M194041</link>
      <description>&lt;P&gt;By configuring your esxi hosts to send their syslog to a separate syslog server.&lt;BR /&gt;
See: &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts#Configure_ESXi_hosts_to_send_data"&gt;https://docs.splunk.com/Documentation/AddOns/released/VMW/ESXihosts#Configure_ESXi_hosts_to_send_data&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;How exactly you setup that syslog server and send the logs from that syslog server to Splunk Cloud is up to you. This can be done in various ways. The classic way of doing it is have the syslog server run rsyslog/syslog-ng which receives the syslog from esxi and write it to files. Then put a UF on the syslog server to read those files and send them to Splunk Cloud.&lt;/P&gt;

&lt;P&gt;More modern approaches involve solutions that enable you to receive syslog data and send it to HEC. E.g. Splunk Connect for Syslog, or using rsyslog/syslog-ng's built in http output modules (requires recent versions of rsyslog / syslog-ng), or using Ryan Faircloth's omsplunkhec.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 15:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-i-forward-vmware-syslog-to-splunk-cloud-without-using/m-p/489105#M194041</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2020-03-09T15:10:23Z</dc:date>
    </item>
  </channel>
</rss>

