Splunk® App for VMware (Legacy)

Installation Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Deploy the Splunk OVA for VMware to create a Data Collection Node

Prerequisites

  • Make sure you have the information you need about your environment before you deploy the Data Collection Node (DCN). See "Prepare to host a data collection node".
  • Download the Splunk OVA for VMware from Splunkbase.
  • Set up forwarding to the port on which the Splunk indexer(s) is configured to receive data. See "Enable forwarding on a Splunk Enterprise instance" in the Forwarding Data manual.
  • The default password for Splunk's admin user is changeme. This is true for all Splunk instances. We recommend that you change the password using the CLI for this forwarder.
  1. Open the vSphere client and log into vCenter Server.
  2. To open the OVA template wizard, click File > Deploy OVF Template.
  3. In the Deploy OVF Template wizard click Deploy from a file or URL, and click Browse…
  4. Browse to the location of your OVA file, splunk_data_collection_node_for_vmware_<version>-<build_number>.ova, and click Next.
  5. Review the OVF template details, and click Next
  6. In the Name and Location screen, enter a new name for the node VM. (You can use the default name.)
  7. Select a data center or folder as the deployment destination for the node VM, and click Next.
  8. On the Host / Cluster screen, select the specific host or cluster where you would like to run the node VM, and click Next.
  9. In the Datastore screen, choose the datastore where you want the VM and its file system to reside, and click Next. The datastore can be from 4GB to 10GB.
  10. On the Disk Format screen, select Thick Provisioning, and click Next.
  11. On the Network Mapping screen, use the Destination Networks menu to map your data collection node .ova template to one of the networks in your inventory, and to to specify the networks that you want the deployed template to use.
  12. Verify your selections, and click Next to begin deployment.
  13. Click Close to complete the installation and exit the wizard.
  14. Assign resources to your VM according to the data collection node resource requirements listed above.
  15. Locate the collection node VM in the vSphere Client tree view.
  16. Right-click on the collection node VM and choose Power > Power On from the menu to start the VM. When you power on the data collection node, Splunk starts automatically even though the VMware data collection mechanism is not configured. By default, the node VM boots and gets its network settings via DHCP. You can keep this default setting or you can set a static IP address. If you use DHCP, check the Summary tab in the vSphere client to get the IP address of the node VM.
  17. To ssh into the data collection node use the default user name and password (splunkadmin/ changeme). You automatically land in /home/splunkadmin. Your Splunk platform is installed in /home/splunkadmin/opt.
    splunk edit user admin -password 'newpassword' -role admin -auth admin:changeme
  18. Repeat the above steps to create the required number of DCNs.
  19. Start the DCN virtual machines.
  20. Restart Splunk in each of the locations where you installed the OVA.

Now you can configure the DCNs and the Splunk settings for each DCN.

Last modified on 29 September, 2016
Assign user roles for Splunk App for VMware   Configure the data collection node and system settings

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters