We are forwarding syslog data to an intermediate syslog server, which Splunk picks up and forwards to an Indexer.
We are planning to install Splunk App For VMware, As of now we need to monitor syslog data what will be best recommendation and Vmware app has different sourcetype & index, Do i need to make changes in intermediate forwarder or app/addon?