Splunk® Supported Add-ons

Splunk Add-on for VMware

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Hardware and software requirements for the Splunk Add-on for VMware

Current add-on version Supported versions of VMware vCenter Server Supported versions of Splunk Enterprise
4.0.3 6.5, 6.7, 7.0 8.0.x, 8.1.x, 8.2.0

All of the system requirements for the Splunk platform apply for the Splunk software that you use to run this add-on. The Splunk Add-on for VMware does not support scheduler and Data Collection Node functions on Windows operating systems. Linux or UNIX are required. When deploying the VMware add-on into a Windows-based Splunk environment, deploy Linux-based virtual appliances from the Splunk-provided OVA image for both scheduler and data collection node roles.

  • For Splunk Enterprise system requirements: see System Requirements in the Splunk Enterprise Installation Manual.
  • If you are managing on-premises forwarders to get data into Splunk Cloud, see System Requirements in the Splunk Enterprise Installation Manual, which includes information about forwarders.

Data Collection Node supports SSL certificate with encrypted private key for Splunk versions 7.3.3 and later, except for Splunk version 8.0.0

Browser support

The Splunk Add-on for VMware supports the the latest version of the following browsers:

  • Firefox
  • Safari
  • Chrome

Data volume requirements

In a typical environment, approximately 250 MB and 350 MB of data can be collected per host per day from your environment. This number varies depending on the volume of log data you collect, and the number of virtual machines that reside on a host. See the information below for further details.

Collected data type Data volume
Total vCenter logs 15 MB of data per host per day per vCenter. For example, 750MB in a 50 host environment.
ESXi host logs 185 MB of data per host per day. (In a typical environment this number can range from 135MB to 235M of data, but it can vary widely depending on your environment).
Total API data per host 10 MB of data per host per day.
Total API data per virtual machine 3 MB of data per day.

Compatibility with pre-requisite add-on packages

The packages SA-VMWIndex, TA-VMW-FieldExtractions, Splunk_TA_esxilogs, Splunk_TA_vcenter that were included in add-on v4.0.2 or previous are now shipped as individual Splunkbase add-ons as of v4.0.3. Please refer to the table for the add-on version compatibility with the new packages. The given add-ons are pre-requisites for the Splunk Add-on For VMware. Below is the purpose of each add-ons:

  1. Splunk Add-on for VMware Indexes (contains SA-VMWIndex package): Contains the definition of indexes that are used by Splunk Add-on for VMware, Splunk Add-on for vCenter Logs, and Splunk Add-on for VMware ESXi Logs.
  2. Splunk Add-on for VMware Extractions (contains TA-VMW-FieldExtractions package): Contains the field extractions for the data ingested by Splunk Add-on for VMware and search-time extractions used in Splunk App for VMware.
  3. Splunk Add-on for VMware ESXi logs (contains Splunk_TA_esxilogs package): Contains inputs, search-time and Index-time extractions for the collection, parsing, and ingestion of VMware ESXi logs in the Splunk environment.
  4. Splunk Add-on for vCenter Logs (contains Splunk_TA_vcenter package): Contains the inputs, search-time and index-time extractions for the collection, parsing, and ingestion of vCenter logs in the Splunk environment.
Splunk Add-on for VMware version Compatible Splunk Add-on for VMware Indexes version Compatible Splunk Add-on for VMware Extractions version Compatible Splunk Add-on for VMware ESXi Logs version Compatible Splunk Add-on for VMware vCenter Logs version
4.0.3 4.0.3 4.0.3 4.2.1 4.2.1

Version compatibility

Compatible Splunk platform version Compatible Splunk Add-on for VMware version Compatible vCenter version Compatible vSphere version Compatible ESXi version Compatible SA-Hydra version Compatible SA-VMWNetAppUtils version
6.3 to 6.5 3.3.1 5.0 to 6.0 4.1, 5.0, 5.0 Update 1, 5.1, 5.5, 5.5a, 6.0 4.1, 5.0, 5.0 Update 1, 5.1, 5.5 on 64-bit x86 CPUs, 5.5 update 1 and above. 4.0.2 and above 3.5.0, 3.7.0
6.3 to 6.5 3.3.2 5.0,6.0,6.5 4.1, 5.0, 5.0 Update 1, 5.1, 5.5, 5.5a, 6.0 4.1, 5.0, 5.0 Update 1, 5.1, 5.5 on 64-bit x86 CPUs, 5.5 update 1 and above. 4.0.4 1.0.0 (Version 3.3.2 replaces SA-Utils with SA-VMNetAppUtils
6.4 to 6.6 3.4.0 5.5,6.0,6.5 5.5,6.0,6.5 5.5,6.0,6.5 4.0.5 1.0.1
6.5 to 7.0 3.4.1 5.5,6.0,6.5 5.5,6.0,6.5 5.5,6.0,6.5 4.0.6 1.0.2
6.6 to 7.1 3.4.2 5.5,6.0,6.5 5.5,6.0,6.5 5.5,6.0,6.5 4.0.7 1.0.3
7.0 to 7.2 3.4.3 5.5,6.0,6.5,6.7 5.5,6.0,6.5,6.7 5.5,6.0,6.5,6.7 4.0.8 1.0.4
7.0.0 to 7.2.1 3.4.4 5.5,6.0,6.5,6.7 5.5,6.0,6.5,6.7 5.5,6.0,6.5,6.7 4.0.8 1.0.5
7.1.0 to 7.3.1 3.4.5 6.0,6.5,6.7 6.0,6.5,6.7 6.0,6.5,6.7 4.0.9 1.0.5
7.2.x to 8.0.0 3.4.6 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.0 1.0.5
7.2.x to 8.0.x 3.4.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.1 N/A
7.2.x to 8.0.x 4.0.0 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.2 N/A
7.2.x to 8.1.0 4.0.1 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.3 N/A
7.3.x to 8.2.0 4.0.2 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.5 N/A
8.0.x to 8.2.0 4.0.3 6.5, 6.7, 7.0 6.5, 6.7, 7.0 6.5, 6.7, 7.0 4.1,7 N/A
8.0.x to 8.2.x 4.0.3 6.0, 6.5, 6.7 6.0, 6.5, 6.7 6.0, 6.5, 6.7 4.1.7 2.0.3

Requirements for installing Splunk Add-on for VMware with other add-ons

The following requirements apply to installing Splunk Add-on for VMware and Splunk Add-on for VMware Metrics in the same environment:

Splunk Add-on for VMware Metrics version Splunk Add-on for VMware version Can DCS be installed on the same machine? Can DCN be installed on the same machine?
4.0.0 or later 3.4.7 Yes No
1.0.0, 1.1.0 or 1.1.1 (Splunk VMware Add-on for ITSI) 3.4.7 No No

The following requirements apply to installing Splunk Add-on for NetApp ONTAP and Splunk Add-on for VMware in the same environment:

Splunk Add-on for NetApp ONTAP version Splunk Add-on for VMware version Can DCS be installed on the same machine? Can DCN be installed on the same machine?
3.0.0 or later 3.4.6 or later No No
2.1.91 or before 3.4.5 or before Yes No
Last modified on 12 October, 2021
PREVIOUS
Release history for Splunk Add-on for VMware
  NEXT
Installation and configuration overview for the Splunk Add-on for VMware

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters