Splunk® App for VMware (Legacy)

Installation Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Collect Windows VMware vCenter Server log data

You do not need to collect log data from Windows VMware vCenter Servers to see a working version of the Splunk App for VMware.

Install the Splunk Technology Add-on for VMware vCenter to collect vCenter Server log data. Use a Splunk Universal Forwarder to forward the log data from your Windows vCenter Server to the indexer.

1. Install a Splunk forwarder.

2. Configure forwarding. Configure the forwarder on your vCenter Server systems to send data to your indexers. Configure the forwarder in the outputs.conf file for each forwarder installed on a vCenter Server system. See Configure forwarding with outputs.conf.

3. Change your Splunk password.

4. Install Splunk_TA_vcenter.

  • Get the file Splunk_TA_vcenter-<version>-<build_number>.zip from the download package and install it on your vCenter Server systems.
  • Unzip the file, "Splunk_TA_vcenter-<version>-<build_number>.zip", into the apps directory under %SPLUNK_HOME%\etc\apps. When installing on a universal forwarder the path is C:\Program Files\SplunkUniversalForwarder\etc\apps otherwise it is C:\Program Files\Splunk\etc\apps.

5. Restart Splunk Enterprise. See "Start and stop Splunk" in the Admin Manual.

6. In %SPLUNK_HOME%\bin run the command splunk restart. Alternatively, select Start > Administrative Tools > Services > Splunkd restart in Windows services.

Splunk App for VMware collects log data from your Windows vCenter Server systems and forwards the data from vCenter Server to your Splunk indexers or combined indexer search heads.

Last modified on 22 June, 2016
 

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters