Default Version 0.3.0
September 14, 2025
September 14, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x
Log in to rate this app
#13 in Virtualization
Technology Add-on for VMware ESXi Syslog (Community) parses VMware ESXi syslog and normalizes key events to Splunk CIM. It extracts rich fields from hostd/vmkernel/vSAN/Envoy/Rhttpproxy and more, adds Authentication and Web (proxy) tagging, and includes a simple overview dashboard. Works with generic syslog (sourcetype=vmw-syslog) across 6.x–8.x ESXi log formats without requiring index-time changes.
Log in to report this app listing.