Splunk® App for VMware (Legacy)

Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Configure performance data collection

This topic discusses how to improve the performance of the vCenter server when you see performance issues during data collection.

You can limit the processing (reduce the memory and cpu load) on the vCenter server during data collection when you see performance issues with your vCenter server. How performance data is collected in the Splunk Add-on for VMware is specified in the file ta_vmware_collection.conf. The parameter perf_format_type is set to one of two modes:

  • csv mode. The response from the ESXi host when collecting performance data is parsed by vCenter. Performance data is collected by the Splunk App for VMware, from vCenter, by default, using csv mode.
  • normal mode. The response from the ESXi host when collecting performance data is parsed by the data collection nodes. This reduces the load on vCenter.

To change modes, edit a local version of etc/apps/Splunk_TA_vmware/default/ta_vmware_collection.conf, and change the value of perf_format_type to normal. Processing performance data is now done on the data collection node.

Last modified on 21 July, 2016
Configure data collection for hosts   Change data collection node capabilities and log levels

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters