Hi! I've followed this guide to forward syslogs from ESX 4.0 U2 (http://www.splunk.com/wiki/Community:VMwareESXSyslog). But I'm not seeing logs appear on my Splunk server. What steps can I take to troubleshoot this? There's no firewall between the ESX hosts and the Splunk server. Splunk is running on a VM, but that shouldn't be a problem, I'm guessing?
I have to set the timezone as stated in the http://wiki.splunk.com/Community:VMwareESXSyslog doc by using below syntax,
if I have 8 hosts that are named such as,
cd.esx1.mail.....cd.esx6.mail and cd.svm1.mail...cd.svm3.mail
Can I use the below syntax ?
If not, could you please suggest me the most correct way to use the above syntax ?