Splunk® App for VMware (Legacy)

Installation Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Upgrade

This topic describes how to upgrade Splunk App for VMware to the latest released version. Splunk App for VMware 3.1.2 runs on Splunk Enterprise version 6.0.2 or later. If you are running an earlier version of Splunk Enterprise, see "How to upgrade Splunk Enterprise" in the Splunk Enterprise Installation Manual.

Upgrade Splunk App for VMware and the data collection node

1. Download Splunk App for VMware 3.1.2 from Splunk Apps.

2. Move the downloaded zip file to the location in your environment where you installed the previous version of Splunk App for VMware ($SPLUNK_HOME/etc/apps).

3. Stop Splunk Enterprise.

4. Extract splunk-app-for-vmware_312.zip.

5. Move the splunk_app_for_vmware-3.1.2-<build_number>.zip file from the app directory into $SPLUNK_HOME.

6. Extract the app zip file in $SPLUNK_HOME. The file automatically unzips into the $SPLUNK_HOME/etc/apps directory. Choose "Replace all" if prompted.

a. If you are not using the data collection node OVA, move the splunk_forwarder_for_vmware-3.1.1-<build>.zip file to $SPLUNK_HOME on the data collection node.
b. Extract the forwarder zip file in $SPLUNK_HOME. The file automatically unzips into the $SPLUNK_HOME/etc/apps directory. Choose "Replace all" if prompted.

7. Confirm that the following data collection components exist in $SPLUNK_HOME/etc/apps:

  • SA-Utils/…
  • SA-Hydra/…
  • SA-Threshold/…
  • SA-VMW-HierarchyInventory/…
  • SA-VMW-LogEventTask/…
  • SA-VMW-Performance/…
  • SA-VMW-Licensecheck/…
  • Splunk_TA_vcenter/…
  • splunk_for_vmware/…
  • Splunk_TA_vmware/…
  • Splunk_TA_esxilogs/…


8. Open the $SPLUNK_HOME/etc/apps/splunk_for_vmware/local/app.conf file in a text editor.

9. Change the value of is_configured to 0. By default, the existing app sets this value to 1 to prevent the display of the setup page each time you launch the app. However, with an upgrade, you should revisit the setup page to delete any unnecessary legacy add-ons.

10. Upgrade from version 3.0.1 or earlier: To upgrade the .ova for the data collection node included in Splunk App for VMware 3.0.1 or earlier, complete the following steps:

a. Create SSL certificates using the following command: $SPLUNK_HOME/bin/splunk createssl web-cert
b. Update iptables in Linux to enable port 8008. 8008 is the default port for the gateway.

11. Start Splunk Enterprise. If you are not using the data collection node OVA, start Splunk Enterprise on the data collection node.

12. Access the Splunk App for VMware. When the app launches, it displays the setup page. Be sure to check Delete all deprecated Add-ons. This action instructs the app to automatically remove any unecessary legacy add-ons from the new version of the app.

Note: Be sure to remove the SA-VMW-Licensecheck folder from the $SPLUNK_HOME/etc/apps folder of every server upon which you installed the Splunk App for VMware. If you had installed the app on multiple indexers or forwarders, follow the steps below to manually remove the folder from each installation of the app.

Manually remove legacy add-ons

If you launched Splunk App for VMware but did not check Delete all deprecated Add-ons on the setup page, you can manually remove unecessary legacy add-ons from your installation.

1. Stop your instance of Splunk Enterprise.

2. Access the $SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local directory, and delete the hydra_job.conf file on your search head.

3. Remove the SA-VMW-Licensecheck folder from the $SPLUNK_HOME\etc\apps folder on your search head. Note: Be sure to remove the SA-VMW-Licensecheck folder from the /etc/apps folder of every server upon which you installed the Splunk App for VMware.

3. Upgrade from 2.5.0 or earlier: Access the $SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local directory, and delete the following files:

  • DA-VMW-HierarchyInventory
  • DA-VMW-LogEventTask
  • DA-VMW-Performance

4. Restart your instance of Splunk Enterprise.

Last modified on 02 December, 2014
Set Splunk App for VMware trial license to work with remote license master  

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.1.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters