Splunk® Supported Add-ons

Splunk Add-on for Microsoft Hyper-V

Troubleshoot the Splunk Add-on for Microsoft Hyper-V

General troubleshooting

For troubleshooting tips that you can apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.

Cannot launch add-on

This add-on does not have views and is not intended to be visible in Splunk Web. If you are trying to launch or load views for this add-on and you are experiencing results you do not expect, turn off visibility for the add-on.

For more details about add-on visibility and instructions for turning visibility off, see Check if the add-on is intended to be visible or not in the Splunk Add-ons Troubleshooting topic.

Data loss after Hyper-V server restart

When a Microsoft Hyper-V server fails or is restarted, you may encounter data loss if your forwarder collecting data from that machine is not restarted manually after the Hyper-V failure/restart. When your Microsoft Hyper-V server restarts, your forwarder automatically restarts with the Microsoft Hyper-V server. However, you may need to restart the forwarder manually again to prevent data loss.

<![CDATA[]]> embedded in extracted fields for Splunk 7.x

If you are seeing events whose fields are embedded with "CDATA" such as:


Upgrade the Splunk Add-on for Microsoft Hyper-V to version 3.1.0 and install on any Splunk 7.x deployments that you are using to run this add-on.

Last modified on 29 July, 2021
Configure inputs for the Splunk Add-on for Microsoft Hyper-V   Source types for the Splunk Add-on for Microsoft Hyper-V

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters