Splunk® Supported Add-ons

Splunk Add-on for EMC VNX

Hardware and software requirements for the Splunk Add-on for EMC VNX

Splunk admin requirements

To install and configure the Splunk Add-on for EMC VNX, you must be member of the admin or sc_admin role.

Hardware requirements

Because this add-on runs on Splunk Enterprise, all of the Splunk Enterprise system requirements apply.

Performance of data gathering is dependent on many factors, such as VNX system load, Splunk Enterprise system load, and environmental factors such as network latency.

A heavy forwarder should gather data from no more than 10 Filers and 10 Blocks, at 4,000 LUNs each. You can alter load characteristics by increasing or decreasing the scheduling of data gathering events.

The amount of data gathered can vary greatly depending on configuration and scheduling. At maximum load, each Filer and Block pair may produce up to 450 MB per day of data.

Software requirements

The Splunk Add-on for EMC VNX depends on naviseccli. Linux systems require OpenSSH utilities, and Windows systems require plink.exe. Windows systems also require psexec.exe.

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.


The Splunk Add-on for EMC VNX uses EMC's Command Line Interface (CLI) tools to collect VNX data. The naviseccli tool should be installed properly and communicating securely with the VNX infrastructure before you proceed.

Additional recommendations

The add-on does not require the ability to modify VNX configuration. It is highly recommended that you create a read-only user account with proper read capabilities on Control Stations and arrays. Ensure the created account on the VNX array is under scope "0".

To avoid time shifting problems in the metrics, time sync all your Splunk Enterprise instances with all arrays and Control Stations by using an NTP server.

Last modified on 21 July, 2021
Release history for the Splunk Add-on for EMC VNX   Installation and configuration overview for the Splunk Add-on for EMC VNX

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters