All Apps and Add-ons

Splunk and VMware, which logs are typically sent to Splunk?

james_dougherty
New Member

Which logs on ESXi from /var/logs are sent to Splunk? Is there an easy way to get an estimated daily size before configuring the host to send logs to Splunk?

Tags (1)
0 Karma
1 Solution

sduff_splunk
Splunk Employee
Splunk Employee

This is answered in the Splunk documentation for the Splunk Add-on for VMware.

The input stanza for ESXi logs is

[monitor:///var/log/.../syslog.log]

https://docs.splunk.com/Documentation/AddOns/released/VMW/Hardwareandsoftwarerequirements#Data_volum...

Collected data type                    Data volume
Total vCenter logs                  15 MB of data per host per day per vCenter
ESXi host logs                      ~185 MB of data per host per day
Total API data per host                10 MB of data per host per day.
Total API data per virtual machine  3 MB of data per day. 

View solution in original post

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

This is answered in the Splunk documentation for the Splunk Add-on for VMware.

The input stanza for ESXi logs is

[monitor:///var/log/.../syslog.log]

https://docs.splunk.com/Documentation/AddOns/released/VMW/Hardwareandsoftwarerequirements#Data_volum...

Collected data type                    Data volume
Total vCenter logs                  15 MB of data per host per day per vCenter
ESXi host logs                      ~185 MB of data per host per day
Total API data per host                10 MB of data per host per day.
Total API data per virtual machine  3 MB of data per day. 
0 Karma

james_dougherty
New Member

Perfect. Thanks! I guess RTFM 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...