Splunk® App for VMware (Legacy)

Installation and Configuration Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Install UF or LF on each vCenter machine

You can use a Splunk UF or LF to forward the data from your vCenter Server to the Indexer.

To download the Universal Forwarder (UF)

  1. Go to www.splunk.com and click the Free Download button.
  2. Select the Universal Forwarder link on the page. The Download Splunk Universal Forwarder page opens where you can select the forwarder version you need.

To download a Light Forwarder

  1. Go to www.splunk.com and click Free Download button to download a full version of Splunk.
  2. Click on the Splunk version for your target OS to begin the download.
  3. When the download is complete, configure the Splunk instance as a LF.

Configure forwarding

Configure the forwarder on your vCenter Server machines to send data to your indexer(s) in the outputs.conf file. Do this for each forwarder installed on a vCenter machine. For more information about setting up forwarding for your indexers, see Configure forwarders with outputs.conf in the Splunk Distributed Deployment Manual.

For a single indexer configuration:

  1. Use the splunkadmin user to log into vCenter and enter the following:
    splunk add forward-server <host>:<port>
    For example,
    splunk add forward-server splunkindexer.company.com:9998
  2. Now enter the default Splunk credentials to log into the Splunk forwarder on the vCenter, or use the credentials you created. The default username is admin and the password is changeme.
  3. Check that the indexer is active and that you can forward data to it. Run the command:
    splunk list forward-server.
  4. The indexer to which you are forwarding data is added the list of active forward servers.

You can now forward data from the vCenter to your indexer/search head.

To learn more about installing and configuring forwarders, in the Splunk Distributed Deployment Manual:

Last modified on 30 January, 2013
PREVIOUS
Create vCenter service accounts
  NEXT
Install the App

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 1.0, 1.0.1, 1.0.2, 1.0.3, 2.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters