All Apps and Add-ons

Splunk and VMware, which logs are typically sent to Splunk?

james_dougherty
New Member

Which logs on ESXi from /var/logs are sent to Splunk? Is there an easy way to get an estimated daily size before configuring the host to send logs to Splunk?

Tags (1)
0 Karma
1 Solution

sduff_splunk
Splunk Employee
Splunk Employee

This is answered in the Splunk documentation for the Splunk Add-on for VMware.

The input stanza for ESXi logs is

[monitor:///var/log/.../syslog.log]

https://docs.splunk.com/Documentation/AddOns/released/VMW/Hardwareandsoftwarerequirements#Data_volum...

Collected data type                    Data volume
Total vCenter logs                  15 MB of data per host per day per vCenter
ESXi host logs                      ~185 MB of data per host per day
Total API data per host                10 MB of data per host per day.
Total API data per virtual machine  3 MB of data per day. 

View solution in original post

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

This is answered in the Splunk documentation for the Splunk Add-on for VMware.

The input stanza for ESXi logs is

[monitor:///var/log/.../syslog.log]

https://docs.splunk.com/Documentation/AddOns/released/VMW/Hardwareandsoftwarerequirements#Data_volum...

Collected data type                    Data volume
Total vCenter logs                  15 MB of data per host per day per vCenter
ESXi host logs                      ~185 MB of data per host per day
Total API data per host                10 MB of data per host per day.
Total API data per virtual machine  3 MB of data per day. 
0 Karma

james_dougherty
New Member

Perfect. Thanks! I guess RTFM 🙂

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...