Getting Data In

Adding ESX hosts to an existing Splunk server

mikeyw
New Member

Hi,

I've inherited a splunk server that was setup to receive to vmkwarning files from around 20 ESX hosts.

Recently i built another 5 hosts running ESX5 that i'd like to also get the vmkwarning files sent to the splunk server, what's the best guide to show me how to do this ?

I presume some kind of splunk forwarding agent has to reside on the ESX host ?

Thanks

Tags (1)
0 Karma

mikeyw
New Member

Any further thoughts here guys ?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you'll need to install a splunk forwarder on the ESX host. Then you'll set up file monitoring. Take a look at one of your existing ESX server forwarders. You should find settings in /etc/system/local/ in outputs.conf and inputs.conf. Outputs will have the settings for communicating back to the Splunk server and inputs.conf has the details of the file being monitored. In this case probably /var/log/vmkwarning.log.

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Deploymentoverview

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories

0 Karma

mikeyw
New Member

I've just checked on a couple of ESX hosts that the splunk server is collecting log information from and did a global find for both outputs.conf and inputs.conf, nothing was returned. What is the default location for the splunk forwarders on a ESX node ?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...