Getting Data In

Forwarding syslogs from ESX

BlightMan
Explorer

Hi! I've followed this guide to forward syslogs from ESX 4.0 U2 (http://www.splunk.com/wiki/Community:VMwareESXSyslog). But I'm not seeing logs appear on my Splunk server. What steps can I take to troubleshoot this? There's no firewall between the ESX hosts and the Splunk server. Splunk is running on a VM, but that shouldn't be a problem, I'm guessing?

Tags (1)
0 Karma

BlightMan
Explorer

I fixed the issue. There was a typo in the Spunk Syslog Wiki - there was an extra : on the end of one of the lines. I've updated the wiki so the command is correct.

0 Karma

BlightMan
Explorer

I fixed the issue. There was a typo in the Spunk Syslog Wiki - there was an extra : on the end of one of the lines. I've updated the wiki so the command is correct.

0 Karma

damode
Motivator

Hi @BlightMan,

This extra ":" you mentioned, was it under the "Set the timezone" section of that page http://wiki.splunk.com/Community:VMwareESXSyslog ?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi BlightMan

recently I did the same, followed this doc and it worked like a charm.

regards

damode
Motivator

Hi @MuS,

I have to set the timezone as stated in the http://wiki.splunk.com/Community:VMwareESXSyslog doc by using below syntax,
[host::myesx.splunk.com]
TZ=UTC

if I have 8 hosts that are named such as,
cd.esx1.mail.....cd.esx6.mail and cd.svm1.mail...cd.svm3.mail

Can I use the below syntax ?
[host::cd.esx*]
TZ=UTC

[host::cd.svm*]
TZ=UTC

If not, could you please suggest me the most correct way to use the above syntax ?

0 Karma

MuS
SplunkTrust
SplunkTrust

I haven't done it on host yet. Usually I use sourcetype to do such things - so I cannot not really tell if this will work or not sorry ....

0 Karma

damode
Motivator

Hi @MuS,

that link takes to the splunk documentation page.

Can you please post the updated link ?

Thanks,
Deven

0 Karma

MuS
SplunkTrust
SplunkTrust

Link updated 😉

0 Karma

damode
Motivator

Thanks! @MuS

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...