We have noticed that our ESXI hosts are acting as Syslog clients and data from those hosts are being sent to our Syslog Server(port 6514) and then we are redirecting those logs to Splunk.
We noticed that ESXI host stops reporting to Splunk frequently and every time we have to restart the Syslog Server service or need to re-install the splunk vib in esxi host to report again in spunk server.
This issue has been fixed with the latest VMware release 7.0 update 3o.
