Had a couple of questions regarding logging improvements for vCenter 7 (I just upgraded us for v6.5). The Splunk guys have informed me that after I recently upgraded our vCenter to vCenter 7 Splunk logging has gone from 50mb to 10GB.
The logging level is still set to the VMware recommended "info" level...
Couple of questions I have that spring to mind are ...
- Does the new vSphere improved logging simply generate more logs?
- Can certain entries be omitted at a more granular level if we determine there is a specific culprit?
- If we disable remote logging to the Splunk/syslog server will they build up locally on the VC instead presumably?
Incidentally out hosts are still currently running 6.5 not sure if that's relevant?