Getting Data In

ESXi Hosts logs are not forwarding to Splunk

deepak_negi02
New Member

Hi,

I am trying to get the logs from ESXi hosts to Splunk without using the vmware app. There is no intermediate syslog server on which I can install the forwarder. So I had tried to configure the logs forwarding via esxi hosts advance settings option where we I had provided the IP address of my Splunk server and port tcp1514. Somehow I am still not receiving the logs.

Any suggestion how to get the logs? http://wiki.splunk.com/Community:VMwareESXSyslog ...gone through this link and did the same like mentioned before under advance configuration setting of esxi hosts. Any other approach or what mistake i am doing?

0 Karma

damode
Motivator

Hi @deepak_negi02, were you able to make this finally work ? I am facing this same issue.
I have configured port 1515 udp on Splunk for esx syslog using the above method.

0 Karma

kserra_splunk
Splunk Employee
Splunk Employee

Make sure you have the following

  • An inputs.conf setup to receive on tcp 1514 on the receiving side
  • An index to which this data will be sent to on the indexer along with any sourcetype definitions for this data
  • May want to run a packet capture on port 1514 to make sure the traffic is actually getting to receiver.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...