Data collection planning and requirements for the Splunk Add-on for VMware ESXi Logs
Before you deploy the Splunk Add-on for VMware ESXi Logs review these requirements.
Splunk platform version requirements
Current add-on version
|
Supported versions of Splunk Enterprise
|
4.2.1
|
|
VMware index
The ESXi logs data from the forwarder is stored in this index. The Splunk Add-on for ESXi Logs package indexes the data into the vmware-esxihost index. If you are using Splunk Add-on for VMware Metrics, then you need to install Splunk Add-on for VMware Metrics Indexes in your environment to get this index. If you are using Splunk Add-on for VMware, then you need to install Splunk Add-on for VMware Indexes in your environment to get the index.
Index
|
Description
|
vmware-esxihost
|
Stores ESXi host log data.
|
Data volume requirements
The expected ESXi logs data volume ingested by this package in a typical environment is 125-235 MB per host per day. The actual volume varies depending on the log data collected and the number of virtual machines on a host.
Data type
|
Data volumne
|
ESXi host logs
|
135-235 MB per host per day
|
Add-on Version compatibility with Splunk Add-on for VMware Metrics and its prerequisite add-ons
Splunk Add-on for VMware Metrics version
|
Compatible Splunk Add-on for VMware ESXi Logs version
|
Compatible Splunk Add-on for VMware Metrics Indexes version
|
Compatible vCenter version
|
Compatible ESXi version
|
4.2.1
|
4.2.1
|
4.2.1
|
|
|
4.2.4
|
4.2.1
|
4.2.1
|
|
|
Add-on Version compatibility with Splunk Add-on for VMware and its prerequisite add-ons
vCenter versions 5.x and 6.x are End of Life (EOL).
Splunk Add-on for VMware version
|
Compatible Splunk Add-on for VMware ESXi Logs version
|
Compatible Splunk Add-on for VMware Indexes version
|
Compatible vCenter version
|
Compatible ESXi version
|
4.0.3
|
4.2.1
|
4.0.3
|
|
|
4.0.4
|
4.2.1
|
4.0.3
|
|
|
4.0.5
|
4.2.1
|
4.0.3
|
|
|
4.0.6
|
4.2.1
|
4.0.3
|
|
|
Feedback submitted, thanks!