Getting Data In

Adding ESX hosts to an existing Splunk server

mikeyw
New Member

Hi,

I've inherited a splunk server that was setup to receive to vmkwarning files from around 20 ESX hosts.

Recently i built another 5 hosts running ESX5 that i'd like to also get the vmkwarning files sent to the splunk server, what's the best guide to show me how to do this ?

I presume some kind of splunk forwarding agent has to reside on the ESX host ?

Thanks

Tags (1)
0 Karma

mikeyw
New Member

Any further thoughts here guys ?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you'll need to install a splunk forwarder on the ESX host. Then you'll set up file monitoring. Take a look at one of your existing ESX server forwarders. You should find settings in /etc/system/local/ in outputs.conf and inputs.conf. Outputs will have the settings for communicating back to the Splunk server and inputs.conf has the details of the file being monitored. In this case probably /var/log/vmkwarning.log.

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Deploymentoverview

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories

0 Karma

mikeyw
New Member

I've just checked on a couple of ESX hosts that the splunk server is collecting log information from and did a global find for both outputs.conf and inputs.conf, nothing was returned. What is the default location for the splunk forwarders on a ESX node ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...