Skip to content

Commit d401d3a

Browse files
authored
updating raw log (#3756)
1 parent bd66e7a commit d401d3a

1 file changed

Lines changed: 5 additions & 16 deletions

File tree

Lines changed: 5 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: VMWare ESXi Syslog
22
id: f91c5ad1-2a44-4be3-93df-43150fa243e5
3-
version: 1
4-
date: '2025-05-08'
3+
version: 2
4+
date: '2025-11-04'
55
author: Raven Tait, Splunk
66
description: Data source object for syslog data from VMWare ESXi
77
source: vmware:esxlog
@@ -14,19 +14,8 @@ fields:
1414
- _time
1515
- host
1616
- Message
17-
example_log: '{"preview":false,"lastrow":true,"result":{"Application":"May","Message":
18-
"54:23 192.168.8.233 2025-05-08T17:52:34.409Z localhost.lan Hostd[263196]: [Originator@6876
19-
sub=Vimsvc.ha-eventmgr opID=esxui-6983-6230 sid=52eb1a76] Event 854 : User root@192.168.196.95
20-
logged in as Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36
21-
(KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36","_raw":"May 8 17:54:23 192.168.8.233
22-
2025-05-08T17:52:34.409Z localhost.lan Hostd[263196]: [Originator@6876 sub=Vimsvc.ha-eventmgr
23-
opID=esxui-6983-6230 sid=52eb1a76] Event 854 : User root@192.168.196.95 logged in
24-
as Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
25-
Gecko) Chrome/135.0.0.0 Safari/537.36","_time": "2025-05-08T17:52:34.409+0000","date_hour":"17","date_mday":"8","date_minute":"52","date_month":
26-
"may","date_second":"34","date_wday":"thursday","date_year":"2025","date_zone":"0","host":
27-
"192.168.8.233","index":"vmware-esxilog","linecount":"1","opID":"esxui-6983-6230","punct":
28-
"___::_..._--::._._[]:_[@_=.-_=--_=]___:__@...____/","sid":"52eb1a76","source":
29-
"vmware:esxlog:source::udp:514","sourcetype":"vmw-syslog","splunk_server":"splunk",
30-
"sub":"Vimsvc.ha-eventmgr","timeendpos":"54","timestartpos":"30"}}'
17+
example_log: |
18+
Jul 1 14:30:23 192.168.8.233 2025-07-01T14:29:11.508Z localhost.localdomain shell[1627100]: [root]: esxcli system auditrecords local set
19+
Jul 1 14:30:21 192.168.8.233 2025-07-01T14:29:09.506Z localhost.localdomain shell[1627100]: [root]: esxcli system auditrecords local delete
3120
output_fields:
3221
- dest

0 commit comments

Comments
 (0)