Getting Data In

What is the best way to forward Vcenter and ESXi host logs to Splunk?

raomu
Explorer

Hello,

I am working on a project to get logs from Vcenter and ESXi host to Splunk .

question 1 ) Is Vcenter app for splunk is license based ?or is it a free app ?
question 2 ) Can I install Vcenter app on my Splunk Heavy Forwarder and make it act as DNC ( as per documentation, we need to have DNC server, if we pulling logs using API )
question 3 ) what is the best process and to fwd logs from Vcenter and ESXi server to splunk ?

Thanks in advance.

spodda01da
Explorer

Hi raomu, Did you manage to forward VCenter logs to Splunk. If yes, can you please share details and I am having similar issue.

Thanks in advance,

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...