Splunk® App for VMware (Legacy)

Installation and Configuration Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

System Requirements

Before you download and install Splunk for VMware, please check that it is compatible with your Splunk and VMware infrastructure. You should also verify that there are enough resources available in the VMware environment to run the FA VM. Information about the FA VM's internal specifications and required 3rd-Party software packages are also provided below.

Splunk Versions Supported

VMware Versions Supported

  • vCenter Server 4.1, 5.0, 5.0 update 1, and 5.1.
  • ESX/i 4.1, 5.0, 5.0 update 1, and 5.1 on 64-bit x86 CPUs.

Note:

  • We do not support Linked vCenters.
  • We do not support the Linux based vCenter Virtual Appliance. This only affects vCenter log collection. Other data such as ESX/i logs, performance data, tasks/events and so on is not affected by this.

Browsers supported

The Splunk App for VMware supports the browsers listed below:

  • Firefox (latest)
  • Internet Explorer 9 and 10
  • Safari (latest)
  • Chrome (latest)

Note: The Splunk App for VMware does not support IE 8 and does not work in IE 9 Compatibility mode.

The Splunk FA VM resource requirements

  • 2 vCPUs w/ normal "shares" and a 250MHz "reservation".
  • 4 GB memory w/ normal "shares" and a 128 MB "reservation".
  • 20 GB of disk space.

The Splunk FA VM internal specifications

  • VMware OVA file format (Open Virtual Appliance).
  • VMware VM H/W v7.
  • Cent OS 5.7 (RedHat Enterprise Linux) x86_64.
    • DHCP enabled by default.
    • NTP enabled by default.
    • Pacific time zone by default.
  • Splunk configured as a Heavy Forwarder with auto-start pre-enabled.
    • 2.0 GA: Splunk 4.2.5 (x86_64) .
  • Splunk "Forwarder Appliance Add-on for VMware” pre-installed.
  • Unix App (pre-installed, but disabled by default).

Required 3rd-Party Software

  • VMware vSphere™ SDK for Perl version 5.1. This free software packages must be installed for the Splunk Forwarder Virtual Appliance for VMware to work. Download and install the app as part of the deployment process described in this manual.
Last modified on 23 September, 2013
PREVIOUS
Look at the videos
  NEXT
Plan your deployment

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 2.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters