# Logstash filters for VMware VPXA logs

**URL:** <https://discuss.elastic.co/t/logstash-filters-for-vmware-vpxa-logs/54769>\
**Category:** Logstash\
**Created:** [July 5, 2016, 5:38pm UTC](https://discuss.elastic.co/t/logstash-filters-for-vmware-vpxa-logs/54769 "2016-07-05T17:38:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Geezer](https://avatars.discourse-cdn.com/v4/letter/g/49beb7/32.png) [@Geezer](https://discuss.elastic.co/u/Geezer)\
**Post date:** [July 5, 2016, 5:38pm UTC](https://discuss.elastic.co/t/logstash-filters-for-vmware-vpxa-logs/54769/1 "2016-07-05T17:38:07Z")

</div>

Hello,

We are ingesting vmware vpxa logs from our ESX servers into Elasticsearch but parsing is problematic as every agent on the ESX servers seems to have a different message format.

Sexilog produced an ELK appliance for vmware logs but it hasn't been updated in a while: [http://www.sexilog.fr/](http://www.sexilog.fr/)

I've taken the filter-syslog-esxi.conf file from Sexilog's appliance here:

> **[sexibytes/sexilog](https://github.com/sexibytes/sexilog/tree/master/logstash/conf.d)**
>
> sexilog - SexiLog is a specific ELK virtual appliance designed for vSphere environment

This parses most of the messages but does anyone have a working set of Logstash filters for ESX 6 hosts?

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/logstash-filters-for-vmware-vpxa-logs/54769/2 "2017-07-06T04:49:24Z")

</div>


