Splunk® App for VMware (Legacy)

Installation and Configuration Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Go to Splunkbase

Download the Solution

These instructions tell you how to download Splunk for VMware.

Knowing how you want to splunk your VMware environment and deploy and use Splunk for VMware in your environment is essential to getting this App working for you. For more information on deployment considerations, see the core Splunk product documentation.

You must be logged into Splunkbase to download the components of the solution. If you are unable to download the Solution, contact the Splunk Support team using the: Splunk Support Portal and we will get back to you.

We recommend that you

  • Know Splunk and have used it in an enterprise environment before installing and using the Solution. Read the Splunk product documentation for more information on how to get started.
  • Are familiar with VMware and that you understand your VMware infrastructure.
  • Download all of the solution components to a shared folder on your network and then install each component.

What to download

The individual components of the Splunk for VMware Solution are described and available for download from Splunkbase. Download each of the solution components to a shared folder on your network, then install each component.

Download Install it on To…
The application package zip file, splunk_app_vmware-<version>-<build_number>.zip your Splunk indexers/search heads get the supporting add-ons, domain add-ons, technology add-ons, and the apps that are all part of the Solution.
The Splunk Forwarder Virtual Appliance for VMware, splunk_for_vmware_forwarder_appliance_<version>-<build_number>.ova on a Splunk indexer or a non VMware box with a Splunk forwarder installed get a VM created by Splunk and distributed as an OVA (Open Virtual Appliance) file. This component is used to collect data from your ESX/i hosts and vCenter Servers.
The Splunk Technology Add-on for VMware vCenter, Splunk_TA_vcenter-<version>-<build_number>.zip the Splunk forwarder (UF/HF) running on your vCenter machines collect vCenter log data and forward it to the indexer.

Download the 3rd party components

Download vSphere SDK for Perl version 5.1 and install it on the Forwarder Virtual Appliance so that you can access the vSphere API .

Download Splunk App for VMware

Note: You must be the splunkadmin user to do the installation.

  1. For each Splunk indexer/search head in your environment, download Splunk App for VMware from Splunkbase
  2. Splunkbase, click "Download App" and check the license agreement checkbox.
    1. The Solution component is automatically downloaded. Check that the file name is splunk_app_vmware-<version>-<build_number>.zip.
  3. To install the App, see Install Splunk App for VMware in this manual.

Download Splunk Technology Add-on for VMware vCenter

  1. Download the Splunk Technology Add-on for VMware vCenter from Splunkbase
  2. Click "Download Add-on" and check the license agreement checkbox.
    1. The Solution component is automatically downloaded. Check that the file name is Splunk_TA_vcenter-<version>-<build_number>.zip.
  3. To install it on the Splunk forwarder (UF/HF) running on your vCenter machines, see Install the Splunk Technology Add-on for VMware vCenter in this manual.

Download the Splunk Forwarder Virtual Appliance for VMware

Download this component to collect data from your ESX/i hosts and vCenter Servers. This is the data collector VM image that you install using vCenter.

  1. Download the Splunk Forwarder Virtual Appliance for VMware from Splunkbase
  2. On Splunkbase, click "Download" and check the license agreement checkbox.
    1. The Solution component is automatically downloaded. Check that the file name is splunk_for_vmware_forwarder_virtual_appliance-<version>-<build_number>.zip.
  3. Unzip the FA VM zip file to get the OVA file, splunk_for_vmware_forwarder_appliance_<version>-<build_number>.ova. This is the OVA you will deploy using the vSphere client.
  4. To install the FA VM see Install the FA VM in this manual.
Last modified on 09 May, 2013
PREVIOUS
Credentials.pl
  NEXT
Create vCenter service accounts

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 2.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters