Here is a Splunk Wiki that I referenced along with the already mentioned links:
http://www.splunk.com/wiki/Community:VMwareESXSyslog
travis.
VMWare ESXi does not have the full "console OS" like classic ESX does. But, it does support writing its log data to a remote syslog server. Splunk can play the role of this syslog server, receiving this as a UDP input.
Refer to the VMWare doc http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=101662... on configuring VMWare to emit syslog messages over UDP.
Refer to the Splunk doc http://www.splunk.com/base/Documentation/latest/Admin/Monitornetworkports for information on configuring Splunk to accept syslog input via UDP.
One caveat is this may not work with the "Free" version of VMWare ESXi as the free license won't allow it. (I've not tested it, so I don't know for sure)