Getting Data In

ESXi Hosts logs are not forwarding to Splunk

deepak_negi02
New Member

Hi,

I am trying to get the logs from ESXi hosts to Splunk without using the vmware app. There is no intermediate syslog server on which I can install the forwarder. So I had tried to configure the logs forwarding via esxi hosts advance settings option where we I had provided the IP address of my Splunk server and port tcp1514. Somehow I am still not receiving the logs.

Any suggestion how to get the logs? http://wiki.splunk.com/Community:VMwareESXSyslog ...gone through this link and did the same like mentioned before under advance configuration setting of esxi hosts. Any other approach or what mistake i am doing?

0 Karma

damode
Motivator

Hi @deepak_negi02, were you able to make this finally work ? I am facing this same issue.
I have configured port 1515 udp on Splunk for esx syslog using the above method.

0 Karma

kserra_splunk
Splunk Employee
Splunk Employee

Make sure you have the following

  • An inputs.conf setup to receive on tcp 1514 on the receiving side
  • An index to which this data will be sent to on the indexer along with any sourcetype definitions for this data
  • May want to run a packet capture on port 1514 to make sure the traffic is actually getting to receiver.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...