Splunk® Supported Add-ons

Splunk Add-on for VMware Metrics

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Deploy Splunk Add-on for VMware Metrics to your search head

Deploy Splunk Add-on for VMware to your on-prem deployment

Deploy the packages of the Splunk Add-on for VMware ESXi logs and Splunk Add-on for vCenter logs on your search head for the search-time extractions of ESXi logs and vCenter server logs.

  1. Stop your Splunk platform instance.
    1. If you're using a search head cluster, download the folowing Add-on from Splunkbase and add the following packages to opt/splunk/etc/shcluster/apps/ on the deployer.
    2. If you're not using a search head cluster, download the Splunk Add-on for VMware Metrics package from splunkbase and add the following packages to etc/apps:
      Splunkbase name Add-on Description
      Splunk Add-on for VMware ESXi logs Splunk_TA_esxilogs Runs props and transforms for ESXi log data you forward to the DCN. If you don't forward ESXi log data to the DCN and instead forward ESXi log data directly to the indexer tier, you don't have to install this add-on on the DCN.
      Splunk Add-on for vCenter logs Splunk_TA_vcenter Runs props and transforms for vCenter Server log data you forward to the DCN. If you don't forward vCenter Server log data to the DCN and instead forward vCenter Server log data directly to the indexer tier, you don't have to install this add-on on the DCN.
  2. Restart your Splunk platform instance.

Deploy Splunk Add-on for VMware Metrics to your cloud deployment

  1. Login to your Search Head.
  2. On the Splunk Web home page, click the Gear icon next to Apps.
  3. Under the App Management menu, click the Install App button. The Browse More Apps menu appears.
  4. Search for the below-listed add-ons and click the Install button. Not all apps can be installed using the self-service installation.
  5. A confirmation box appears. Review and click Continue.
  6. Enter the Splunk.com login credentials, read and accept the login disclaimer, and click Login and Download.
  7. (Optional) If the App Installation Failed window appears, review the apps or add-ons that are listed as app dependencies, review and accept the terms and conditions of the license(s), and click Install to install the app dependencies for the below add-ons.
  8. On the App Management page, review the installed app.
Splunkbase name Add-on Description
Splunk Add-on for VMware ESXi logs Splunk_TA_esxilogs Runs props and transforms for ESXi log data you forward to the DCN. If you don't forward ESXi log data to the DCN and instead forward ESXi log data directly to the indexer tier, you don't have to install this add-on on the DCN.
Splunk Add-on for vCenter logs Splunk_TA_vcenter Runs props and transforms for vCenter Server log data you forward to the DCN. If you don't forward vCenter Server log data to the DCN and instead forward vCenter Server log data directly to the indexer tier, you don't have to install this add-on on the DCN.
Last modified on 13 September, 2023
PREVIOUS
Deploy the Splunk Add-on for VMware Metrics on your indexers
  NEXT
Configure Splunk Add-on for VMware Metrics to collect data

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters