Splunk® App for VMware (Legacy)

Installation and Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

About the Add-on

Install the Splunk Add-on for vCenter onto your VMware vCenter machines to collect vCenter log data.

Important: We do not support the vSphere 5 VMware vCenter Server Virtual Appliance (a Linux-based virtual machine) on Linux.

Are you ready to install the Add-on

You are ready to install the Add-on, if you have:

  1. Configured your indexers to correctly set the timezone for vCenter (VC) log files in $SPLUNK_HOME/etc/apps/Splunk_TA_vcenter/local/props.conf. See "Set the time zone for vCenter log files".
  2. Installed a universal forwarder (UF) or light forwarder (LF) on your vCenter Server machines, if one did not already exist, so that you can forward data to your indexers.
  3. Created an outputs.conf file (if one did not exist already) on each forwarder on a vCenter machine to send VMware data to your indexers. See "Configure outputs.conf" in this manual. For more information about setting up forwarding, see Configure forwarders with outputs.conf in the Distributed Deployment Manual.

To install the Splunk Add-on for vCenter, you must have:

  1. Login access to your vCenter machines.
  2. An untar utility (such as gzip) on a Windows machine. Get it from http://www.gzip.org/#exe. For more information on how to use this utility, see http://www.mkssoftware.com/docs/man1/gzip.1.asp.
Last modified on 12 September, 2012
Install the App   Install the Add-on

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 1.0, 1.0.1, 1.0.2, 1.0.3, 2.0








You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters