Splunk® App for VMware (Legacy)

Installation and Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Configure forwarding

You must forward the data collected from the FA VM to your indexers. Configure your forwarders to do this. For more information about setting up forwarding for your indexers, see Configure forwarders with outputs.conf in the Splunk Distributed Deployment Manual.

For a single indexer configuration:

  1. Use the splunkadmin user to log into the FA VM and enter the following:
    splunk add forward-server <host>:<port>
    For example,
    splunk add forward-server splunkindexer.company.com:9997
  2. Now enter the default Splunk credentials to log into the Splunk forwarder on the FA, or use the credentials you created for the FA. The default username is admin and the password is changeme.
  3. Check that the indexer is active and that you can forward data to it. Run the command:
    splunk list forward-server.
  4. The indexer to which you are forwarding data is added the list of active forward servers.
Last modified on 21 October, 2013
Install the Perl API package into the FA VM   Create service accounts on ESX(i) hosts

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 1.0, 1.0.1, 1.0.2, 1.0.3, 2.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters