Compatibility
- Splunk Enterprise 8.2+ .
- ESXi 6.x–8.x log formats.
-
Notes
- This is a community add‑on, not affiliated with VMware or Splunk LLC.
- No inputs or index‑time settings are enforced; safe to deploy alongside other ESXi TAs.
Version 0.3.0 — 2025-09-14
- New: Envoy access parser with Web CIM tagging (method, uri, status, src/dest IP:port, upstream, user_agent).
- New: Parsers for backup-check (xmlfile, schemaId), auto-backup.sh (message), and crx-cli (version, build, option).
- Improved: Program detection (explicit support for envoy-access, backup-check, auto-backup.sh, crx-cli) plus safe fallback program extractor.
- Improved: Hostd logout regex (tolerates AM/PM and long “login time” strings).
- Improved: vSAN capacity regex (supports both “osfsd[pid]: …” and “osfsd: info osfsd[pid] …”).
- Added: Compatibility stanzas for Splunk_TA_esxilogs sourcetypes ([source::vmware:esxlog:...], vmkernel/vmkwarning).
- Dashboard: “ESXi: Auth & Storage” visible by default.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.