Splunk® App for VMware (Legacy)

Installation and Configuration Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

System Requirements

Before you download and install Splunk for VMware, please check that it is compatible with your Splunk and VMware infrastructure. You should also verify that there are enough resources available in the VMware environment to run the FA VM. Information about the FA VM's internal specifications and required 3rd-Party software packages are also provided below.

Splunk Versions Supported

Note: There is a known incompatibility between the Splunk App for VMware and Splunk 4.2.1 when run on 64-bit versions of Windows Server 2008. The Solution works with all other Splunk versions.

VMware Versions Supported

  • vCenter Server 4.1, 5.0, and 5.0 update 1.
  • ESX/i 4.1, 5.0, and 5.0 update 1 on 64-bit x86 CPUs.

Note: We do not support the Linux based vCenter Virtual Appliance.

The Splunk FA VM resource requirements

  • 2 vCPUs w/ normal "shares" and a 250MHz "reservation".
  • 4 GB memory w/ normal "shares" and a 128 MB "reservation".
  • 20 GB of disk space.

The Splunk FA VM internal specifications

  • VMware OVA file format (Open Virtual Appliance).
  • VMware VM H/W v7.
  • Cent OS 5.7 (RedHat Enterprise Linux) x86_64.
    • DHCP enabled by default.
    • NTP enabled by default.
    • Pacific time zone by default.
  • Splunk configured as a Heavy Forwarder with auto-start pre-enabled.
    • 1.0 GA: Splunk 4.2.5 (x86_64) .
  • Splunk "Forwarder Appliance Add-on for VMware” pre-installed.
  • Unix App (pre-installed, but disabled by default).

Required 3rd-Party Software

  • Sideview Utils (1.3.1 or later), a free App must that must be installed for the Splunk App for VMware to work. You can download it from Splunkbase at http://splunk-base.splunk.com/apps/Sideview+Utils. Download and install the app as part of the deployment process described in this manual.
  • VMware Perl SDK (5.0 or later). This free software packages must be installed for the Splunk Forwarder Virtual Appliance for VMware to work. Download and install the app as part of the deployment process described in this manual.
Last modified on 30 October, 2012
PREVIOUS
Look at the videos
  NEXT
Plan your deployment

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 1.0, 1.0.1, 1.0.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters