Getting Data In

Adding ESX hosts to an existing Splunk server

mikeyw
New Member

Hi,

I've inherited a splunk server that was setup to receive to vmkwarning files from around 20 ESX hosts.

Recently i built another 5 hosts running ESX5 that i'd like to also get the vmkwarning files sent to the splunk server, what's the best guide to show me how to do this ?

I presume some kind of splunk forwarding agent has to reside on the ESX host ?

Thanks

Tags (1)
0 Karma

mikeyw
New Member

Any further thoughts here guys ?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you'll need to install a splunk forwarder on the ESX host. Then you'll set up file monitoring. Take a look at one of your existing ESX server forwarders. You should find settings in /etc/system/local/ in outputs.conf and inputs.conf. Outputs will have the settings for communicating back to the Splunk server and inputs.conf has the details of the file being monitored. In this case probably /var/log/vmkwarning.log.

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Deploymentoverview

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories

0 Karma

mikeyw
New Member

I've just checked on a couple of ESX hosts that the splunk server is collecting log information from and did a global find for both outputs.conf and inputs.conf, nothing was returned. What is the default location for the splunk forwarders on a ESX node ?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...