Collect Windows VMware vCenter Server log data
You do not need to collect log data from Windows VMware vCenter Servers to see a working version of the Splunk App for VMware.
Install the Splunk Technology Add-on for VMware vCenter to collect vCenter Server log data. Use a Splunk Universal Forwarder to forward the log data from your Windows vCenter Server to the indexer.
- Install a Splunk forwarder.
- Download the Universal Forwarder.
- Install the Universal Forwarder. See Install a Universal Forwarder on Windows.
- Configure forwarding. Configure the forwarder on your vCenter Server systems to send data to your indexers. Configure the forwarder in the
outputs.conf
file for each forwarder installed on a vCenter Server system. See Configure forwarding with outputs.conf. - Change your Splunk password.
- The default password for the Splunk Enterprise admin user is
changeme
. Change the password using Splunk Web. See "Change the admin default password" in the Admin Manual.
- Install the Splunk Add-on for VMware.
- Get the file
Splunk_TA_vcenter-<version>-<build_number>.zip
from the Splunk Add-on for VMware download package and install it on your vCenter Server systems. - Unzip the file,
"Splunk_TA_vcenter-<version>-<build_number>.zip"
, into theapps
directory under%SPLUNK_HOME%\etc\apps
. When installing on a universal forwarder the path isC:\Program Files\SplunkUniversalForwarder\etc\apps
otherwise it isC:\Program Files\Splunk\etc\apps
.
- Restart your Splunk platform deployment. See "Start and stop Splunk" in the Admin Manual.
- In
%SPLUNK_HOME%\bin
run the commandsplunk restart
. Alternatively, select Start > Administrative Tools > Services > Splunkd restart in Windows services.
The Splunk Add-on for VMware collects log data from your Windows vCenter Server systems and forwards the data from vCenter Server to your Splunk indexers or combined indexer search heads.
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.0
Feedback submitted, thanks!