Splunk® Supported Add-ons

Splunk Add-on for VMware

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Source types for the Splunk Add-on for VMware

The Splunk Add-on for VMware collects data from the following sources via:

  • Modular input plus stdout
  • Syslog
  • File monitoring

For information about common information model configurations, see Common information model data model acceleration configurations.

Data source name Source type Event type Collection method
VMInv:Datastore vmware:inv:datastore vmware_inventory
vmware_inv_datastore
vmware_perf_storage
vmware_performance API
VMInv:VirtualMachine vmware:inv:vm vmware_inventory
vmware_inv_tools
vmware_inv_snapshot
vmware_inv_network
vmware_inv_storage
vmware_virtualmachine API
VMInv:ClusterComputeResource vmware:inv:clustercomputeresource API
VMInv:ResourcePool vmware:inv:resourcepool API
VMInv:HostSystem vmware:inv:hostsystem vmware_inventory
vmware_inv_cpu
vmware_inv_mem
vmware_hostsystem
vmware_inv_os API
VMInv:Hierarchy vmware:inv:hierarchy API
VMPerf:VirtualMachine vmware:perf:sys vmware_performance
vmware_perf_os
vmware_perf_uptime
vmware_perf_time_sync API
VMPerf:VirtualMachine vmware:perf:virtualDisk API
VMPerf:VirtualMachine vmware:perf:disk vmware_perf_storage API
VMPerf:VirtualMachine vmware:perf:power API
VMPerf:VirtualMachine vmware:perf:mem vmware_perf_mem API
VMPerf:VirtualMachine vmware:perf:rescpu API
VMPerf:VirtualMachine vmware:perf:cpu vmware_perf_cpu API
VMPerf:VirtualMachine vmware:perf:datastore API
VMPerf:VirtualMachine vmware:perf:net vmware_perf_network API
VMPerf:HostSystem vmware:perf:hbr API
VMPerf:HostSystem vmware:perf:disk vmware_perf_storage API
VMPerf:HostSystem vmware:perf:datastore API
VMPerf:HostSystem vmware:perf:net vmware_perf_network API
VMPerf:HostSystem vmware:perf:storageAdapter API
VMPerf:HostSystem vmware:perf:sys vmware_performance
vmware_perf_os
vmware_perf_uptime
vmware_perf_time_sync API
VMPerf:HostSystem vmware:perf:rescpu API
VMPerf:HostSystem vmware:perf:power API
VMPerf:HostSystem vmware:perf:mem vmware_perf_mem API
VMPerf:HostSystem vmware:perf:storagePath API
VMPerf:HostSystem vmware:perf:cpu vmware_perf_cpu API
VMPerf:HostSystem vmware:perf:vflashModule API
VMPerf:ClusterComputeResource vmware:perf:cpu
vmware:perf:clusterServices API
Username:XYZ vmware:events vmware_alert API
Username:XYZ vmware:tasks API
.../vpxd.log vmware:vclog:vpxd File Monitoring
.../vpxd-profiler.log vmware:vclog:vpxd-profiler File Monitoring
.../vpxd-alert.log vmware:vclog:vpxd-alert File Monitoring
.../vmware/ vmware:vclog File Monitoring
.../cim-diag,log vmware:vclog:cim-diag File Monitoring
vmware:esxilog:source::tcp:1514 vmware:esxlog:Hostd File Monitoring
vmware:esxlog:vmkernel File Monitoring
vmware:esxlog:Vpxa File Monitoring
vmware:esxlog:Fdm File Monitoring
vmware:esxlog:hostd-probe File Monitoring
vmware:esxlog:syslog File Monitoring
vmware:esxlog:crond File Monitoring
vmware:esxlog:smartd File Monitoring
vmware:esxlog:sfcb-CIMXML-Processor File Monitoring
vmware:esxilog:sfcb-vmware File Monitoring
vmware:esxlog:heartbeat File Monitoring
vmware:esxlog:vobd File Monitoring
vmware:esxlog:vmkwarning File Monitoring
vmware:esxlog:shell File Monitoring
vmware:esxlog:vmauthd File Monitoring
vmware:esxlog:sshd File Monitoring
vmware:esxlog:cimslp File Monitoring
vmware:esxlog:slpd File Monitoring
vmware:esxlog:ImageConfigManager File Monitoring
vmware:esxlog:Rhttpproxy File Monitoring
vmware:esxlog:storageRM File Monitoring
vmware:esxlog:root File Monitoring
vmware:esxlog:sfcb-hhrc File Monitoring
Last modified on 13 September, 2023
PREVIOUS
Troubleshoot the Splunk Add-on for VMware
  NEXT
Performance metrics reference

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters