All Apps and Add-ons

How to collect additional ESXi log with Splunk App for VMware ?

tomoyagoto
Explorer

hello, splunkers.

I have question regarding ESXi log collection of Splunk App for VMware.

I've set up Splunk App for VMware 2.0 at vSphere5.1U1 environment. And I noticed it doesn't collect all necessary ESXi logs.

Hostd.log, messags, vpxa.log and vmkernel.log are collected, but Fdm.log is not.

Since vSphere HA log is stored in Fdm, it is essential to collect it.

Is there any way to collect additional ESXi log such as FDM.log ?

Thank you in advance.

P.S.

I'm using ESXi syslogd for ESXi log collection instead, but it would be much better to use Splunk App.

(ESXi syslogd collets Hostd, Rhttpproxy, vpxa, Fdm and vmkernel)

Tags (1)
0 Karma

gavind
Explorer

How about using an external Syslog server here it's and configure it so that it points to that.

http://docs.splunk.com/Documentation/VMW/3.0.1/Install/ConfigureSplunkforESXilogs

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...