Hello everyone. I am a newbie to Splunk. I downloaded and installed the free version of Splunk. I just upgraded my VCenter server in VMWare to 5.1 and installed the syslog collector. I am pointing the syslogs to the new Splunk server. How do I configure Splunk to view syslogs from all ESX hosts? I went into Data Inputs and enabled the UDP Data Input on Port 514. If I do a search and look at the UDP data source that I configured, all I see is data from one of my esx hosts. I have 4 esx hosts, all of which are configured the same way in VMWare. I am not sure why Splunk is not monitoring all 4 hosts....only one of them.
What is the best way for me to configure Splunk so I can view the syslogs of ALL 4 of my ESX hosts?
Thanks,
Brian
... View more