Getting Data In

using Log Insight or VMware and NSX Addon to collect logs from ESXi hosts, vCenter servers, and NSX components?

maede_yavari
Explorer

Hi everyone,

I'm currently using VMware vRealize Log Insight to collect logs from ESXi hosts, vCenter servers, and NSX components. I then forward these logs to Splunk. However, I've noticed that Log Insight doesn't always parse logs correctly. I'm considering switching to direct integration using the Splunk Add-ons for VMware and NSX.

My Questions:

  1. Log Volume Reduction: For those who have used Log Insight, what kind of log volume reduction have you achieved through filtering and aggregation before forwarding logs to Splunk?
  2. License Usage: How does the Splunk license usage compare between using Log Insight for pre-processing and direct ingestion with Splunk Add-ons?
  3. Best Practices: Are there any best practices or tips for optimizing Splunk license usage with either approach?

Context:

  • Current log volume: Approximately 300 GB per day (raw).
  • Goals: Improve log parsing accuracy while optimize Splunk license usage.

Any insights or experiences would be greatly appreciated!

Thanks in advance!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...