Splunk® Supported Add-ons

Splunk Add-on for Microsoft Hyper-V

Release history for the Splunk Add-on for Microsoft Hyper-V

Latest release

The latest version of the Splunk Add-on for Microsoft Hyper-V is version 4.0.0. See Release notes for the Splunk Add-on for Microsoft Hyper-V for the release notes of this latest version.

Version 3.1.0

Version 3.1.0 of the Splunk Add-on for Microsoft Hyper-V was released on April 2, 2019 and is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.6.x and later
CIM 4.12
Platforms Microsoft Windows Server 2012 R2

Microsoft Windows 8.1

Vendor Products Microsoft Hyper-V Server 2012

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

The Splunk Add-on for Microsoft Hyper-V 3.1.0 fixes bugs.

Fixed issues

Version 3.1.0 of the Splunk Add-on for Microsoft Hyper-V fixes the following issues.

Date resolved Issue number Description
2019-02-18 ADDON-20922 Sourcetypes microsoft:hyperv:perf:vm and microsoft:hyperv:vm:disk now extract their fields correctly
2019-02-05 ADDON-21194 GetVM_Inventory input is disabled by default in inputs.conf
2019-02-01 ADDON-19269 Read_latency now shows accurate metrics for disk metrics
2019-01-23 ADDON-20118 In Splunk7.0.x and 7.2.0, some events are no longer embedded with "<![CDATA[CentOS01]]>"
2019-01-20 ADDON-20898 Field alias for field 'hyperv_version' is removed from props.conf
2019-01-10 ADDON-20128 Eventtypes.conf is formatted according to best practices

Known issues

Version 3.1.0 of the Splunk Add-on for Microsoft Hyper-V contains the following known issues.


Date filed Issue number Description
2016-07-21 ADDON-10660 The value of network_usage field is empty if the VM is set more than one network adaptor.
2016-07-21 ADDON-10649, ADDON-10444 This add-on cannot get microsoft:hyperv:perf:datastore if "ERROR User script exception"exists in splunk-powershell.ps1.log
2016-07-07 ADDON-10462 Several events contain a value of "" for vm_os_version, vm_os, vm_id, and vm_name fields.
2016-04-17 ADDON-8727 Eventtypes have been changed to adhere to current best practices.

Workaround:
See the Upgrade the Splunk Add-on for Microsoft Hyper-V for details. 

Third-party software attributions

Version 3.1.0 of the Splunk Add-on for Microsoft Hyper-V does not incorporate any third-party software or libraries.

Version 3.0.0

Version 3.0.0 of the Splunk Add-on for Microsoft Hyper-V was released on August 7, 2016 and is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.3.2 and later
CIM 4.4 and above
Platforms Microsoft Windows Server 2012 R2

Microsoft Windows 8.1

Vendor Products Microsoft Hyper-V Server 2012

New features

Version 3.0.0 of the Splunk Add-on for Microsoft Hyper-V includes the following new features:

Date Issue number Description
2016-06-08 ADDON-8090 This add-on added microsoft:hyperv:perf:datastore, microsoft:hyperv:perf:vm and microsoft:hyperv:perf:host sourcetypes collected via powershell.
2016-06-08 ADDON-9003 Mapping to ITSI data model.

Fixed issues

Version 3.0.0 of the Splunk Add-on for Microsoft Hyper-V has no fixed issues.

Known issues

Version 3.0.0 of the Splunk Add-on for Microsoft Hyper-V contains the following known issues.

Date Issue number Description
2016-07-22 ADDON-10660 The value of network_usage field is empty if the VM is set more than one network adaptor.
2016-07-22 ADDON-10649 This add-on cannot get microsoft:hyperv:perf:datastore sourcetype data if the error message
ERROR User script exception: : The data in one of the performance counter samples is not valid. View the Status property for each PerformanceCounterSample object to make sure it contains valid data.

exists in splunk-powershell.ps1.log.

2016-07-10 ADDON-10462 This add-on cannot get values of the field ip, vm_os and vm_os_version in sourcetype microsoft:hyperv:vm under certain circumstances. e.g, The VM is shutdown.

And this add-on cannot get values of serial, root_path and datastore_version in sourcetype microsoft:hyperv:vm:disk if Virtual hard disk is selected in MS Hyper-V VM configuration.

2016-07-10 ADDON-10461 This add-on cannot get the Powershell data in if you don't restart the Splunk again when the Microsoft Hyper-V server failed or restarted.
2016-04-18 ADDON-8727 Change the names of event types from the previous version to meet the naming convention best practice. It breaks backwards compatibility of the eventtypes. See Upgrade suggestion if you upgrade Splunk Add-on for Microsoft Hyper-V from the previous version.
2016-05-03 ADDON-8096 Performance events generated through perfmon appear timestamp-delayed by 30 minutes more than current system timestamp.

Third-party software attributions

Version 3.0.0 of the Splunk Add-on for Microsoft Hyper-V does not incorporate any third-party software or libraries

Version 2.0.1

Version 2.0.1 of the Splunk Add-on for Microsoft Hyper-V is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 6.1 or later
CIM 3.0 or later
Platforms Windows 2012
Vendor Products Microsoft Hyper-V 2012

New features

Version 2.0.1 of the Splunk Add-on for Microsoft Hyper-V includes the following new features:
CIM 4.0 compliance

Fixed issues

Resolved date Defect number Description
2014-09-23 ADDON-2052 Hyper-V eventgen contains wrong path

Known issues

Version 2.0.1 of the Splunk Add-on for Microsoft Hyper-V has no known issues.

Third-party software attributions

Version 2.0.1 of the Splunk Add-on for Microsoft Hyper-V does not incorporate any third-party software or libraries.

Last modified on 29 July, 2021
Release notes for the Splunk Add-on for Microsoft Hyper-V  

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters