Logs do not come. Where I missed?
The VMware deployment is quite complex:
http://docs.splunk.com/Documentation/AddOns/released/VMW/Collectionconfiguration
However, assuming you just want to capture the syslog, have you configured a UDP input on your heavy forwarder/indexer?
The TA wont set this up for you.
If you have, then its all the usual suspects to check next, addresses/firewalls/routes etc,