I went ahead and filed a support request, and turns out this is a bug after all. The splunk folks gave me this search as a workaround:
index="vmware" | search sourcetype=vmware_syslog earliest=-10m
Edit:
Apparently this isn't a bug and I was doing it wrong. The format should have had sourcetype:: prepended to it. So the transform stanza should have looked like this:
[vmware_set_sourcetype]
SOURCE_KEY=MetaData:Host
DEST_KEY=MetaData:Sourcetype
REGEX=^host::vmware-\d+.example.com$
FORMAT=sourcetype::vmware_syslog
... View more