VMware ESXi hosts only can forward logs via TCP:514, UDP:514, and SSL:1514.
I have 2 IDR servers, but 6 (and growing) VMware hosts. There’s no integration (sad face), so how are you guys ingesting syslogs from VMware ESXi hosts?
I can only put an event source on one port, so right now I could have 4… I think I need something in the middle to listen on UDP port 514, say “This is from host 1, so send it to IDRServer1 Port 9001” or “This is from host 2, so send it to IDRServer1 Port 9002”.
you are right you can only use a port/protocol once per collector. However you can send multiple sources to that one port, the caveat here is that all of those sources will be under the same log in log search.
If this is not desirable you could leverage something like this