I am using the VMware Syslog collector to collect the logs from my ESXi hosts and send them to Splunk with the universal forwarder. Everything was working great until I restarted the server with the Syslog collector and the universal forwarder today. The logs are no longer being forwarded or Splunk is not indexing the received messages, what could cause this?
I know it is not a problem with the VMware Syslog collector because the service is running fine and the logs are being updated from the ESXi hosts.
Any ideas on what causes this after a restart?
... View more