Splunk® Supported Add-ons

Splunk Add-on for Microsoft Hyper-V

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for Microsoft Hyper-V

About this release

Version 4.0.0 of the Splunk Add-on for Microsoft Hyper-V was released on July 26, 2021 and is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.0.x, 8.1.x, 8.2.x
CIM 4.18.1
Platforms Microsoft Windows Server 2012 R2

Microsoft Windows Server 2016 Microsoft Windows Server 2019 Microsoft Windows 8.1

Vendor Products Microsoft Hyper-V Server 2012

Microsoft Hyper-V Server 2016
Microsoft Hyper-V Server 2019

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

New features

The Splunk Add-on for Microsoft Hyper-V 4.0.0 includes the following improvements:

  • Support of the latest versions of Microsoft Hyper-V server 2016 and Microsoft Hyper-V Server 2019
  • Enhanced CIM v4.18.1 compatibility and mappings:
    • Source-based CIM field extractions for WinEventLog inputs.
    • Removed alerts tag from WinEventLog sourcetypes and mapped events to Change DM.
    • Updates hyperv_alerts eventtype to source based from sourcetype based.
    • Removed unused resource tag from microsoft:hyperv:* sourcetypes.
    • Removed snapshot tag from microsoft:hyperv:perf:vm and microsoft:hyperv:vm:network sourcetypes.
    • Addednew event types for enhancing CIM mappings:
      • hyperv_vm_snapshot
      • wineventlog_compute_admin_change
      • wineventlog_hypervisor_operational_change
      • wineventlog_synthnic_admin_change
      • wineventlog_vmswitch_operational_change
      • wineventlog_vmms_admin_change
      • wineventlog_vmms_networking_change
      • wineventlog_vmms_operationl_change
      • wineventlog_worker_admin_change

Fixed issues

Version 4.0.0 of the Splunk Add-on for Microsoft Hyper-V fixes the following issues.

Date resolved Issue number Description
2021-06-14 ADDON-10462 Several events contain a value of "" for vm_os_version, vm_os, vm_id, and vm_name fields.

Known issues

Version 4.0.0 of the Splunk Add-on for Microsoft Hyper-V contains the following known issues.

Third-party software attributions

Version 4.0.0 of the Splunk Add-on for Microsoft Hyper-V does not incorporate any third-party software or libraries.

Last modified on 29 July, 2021
Source types for the Splunk Add-on for Microsoft Hyper-V
Release history for the Splunk Add-on for Microsoft Hyper-V

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters