Splunk® Supported Add-ons

Splunk Add-on for VMware

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for Splunk Add-on for VMware

Version 4.0.3 of the Splunk Add-on for VMware was released on July 13, 2021.

Version 4.0.3 of Splunk Add-on for VMware only contains Splunk_TA_vmware and SA-Hydra packages. The SA-VMWIndex, TA-VMW-FieldExtractions, Splunk_TA_vcenter, Splunk_TA_esxilogs packages that were part of add-on build in v4.0.2 or below, have been removed from the add-on and are published as individual apps on Splunkbase.

What's New

For Version 4.0.3, the Splunk Add-on for VMware is now updated to use jQuery v3.5.0. The add-on uses jQuery v3.5 in the Splunk version 8.2 or later. This makes the add-on more secure by fixing known cross-site scripting (XSS) related vulnerabilities as well as vulnerabilities created by object prototype pollution. The Splunk Add-on for VMware packages now supports self-service installation in cloud environments. The following packages have been removed from the add-on package and published as individual add-ons on Splunkbase to support self-service installation in cloud environments.

Package Splunkbase Add-on Version
SA-VMWIndex Splunk Add-on for VMware Indexes 4.0.3
TA-VMW-FieldExtractions Splunk Add-on for VMware Extractions 4.0.3
Splunk_TA_esxilogs Splunk Add-on for VMware ESXi Logs 4.2.1
Splunk_TA_vcenter Splunk Add-on for vCenter Logs 4.2.1

In the Splunk Add-on for VMware version 4.0.2, occurrences of biased terms such as master, slave, blacklist, and whitelist have been replaced with appropriate non-biased terms. The occurrences of biased terms that are Splunk platform references or present in the third-party library have not been removed.

The Splunk Add-on for VMware version 4.0.1 and Splunk App for VMware version 4.0.1 must be in the same cloud environments. This makes the installation procedure for the Splunk App and Add-on for VMware easier in cloud environments.

Version 3.4.2 of the Splunk Add-on for VMware has a new component SA-VMWIndex, which has all VMware indexes.

Version 3.4.3 of the Splunk Add-on for VMware has a new component TA-VMW-FieldExtractions, which has search time knowledge objects.

Version 3.4.5 of the Splunk Add-on for VMware supports Splunk Enterprise version 7.3.1.

Version 3.4.6 of Splunk Add-on for VMware (except SA-VMNetAppUtils package) provides Python 3 support in Splunk Enterprise. It supports Splunk Enterprise version 8.0.0 in either Python 2 or Python 3 mode (after removing SA-VMNetAppUtils package), 7.3.x, 7.2.x. Also, the collection configuration page of the VMware TA is redesigned to make it compatible with Splunk version 8.0.0.

Version 3.4.7 of the Splunk Add-on for VMware now uses Python 3 interpreter by default on Splunk 8.x, it will use Python 2 for Splunk 7.x versions. Version 3.4.7 of the Splunk Add-on for VMware is FIPS compliant. Also, it does not contain the SA-VMNetAppUtils component, which is now part of the Splunk App for VMware package and is required on Search heads only.

The Splunk Add-on for VMware version 4.0.0 and Splunk App for VMware version 4.0.0 must be in the same cloud environments. This makes the installation procedure for the Splunk App and Add-on for VMware easier in cloud environments.

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

Upgrade from version 4.0.2 to 4.0.3

See the steps to upgrade from the Splunk Add-on for VMware from v4.0.2 to v4.0.3. If you are using a version previous to 4.0.2, follow the steps to upgrade to v4.0.2 first.

Upgrade from versions 3.4.6 and earlier

In the release 3.3.2, the SA-Utils component has been renamed to SA-VMNetAppUtils. It does not change the input and dashboard you configured in Splunk Add-on for VMware and Splunk App for VMware.

In the release 3.4.2, a new component, SA-VMWIndex has been added to the Splunk Add-on for VMware package. This component contains the indexes.conf which has the definitions of all the indexes [vmware-perf, vmware-inv, vmware-taskevent, vmware-vclog, vmware-esxilog]. The indexes.conf will be removed from all the components of VMware Add-on as these have been added to SA-VMWIndex.

In the release 3.4.3, a new component, TA-VMW-FieldExtractions has been added to the Splunk Add-on for VMware package. This component contains the search time knowledge objects. The search time knowledge objects have been removed from Splunk_TA_vmware .

See the upgrade section of the Splunk App for VMware manual for the detailed procedures.

Note: Splunk recommend you backup your existing deployment before upgrade.
See "Back up configuration information" in the Admin Manual and "Back up indexed data" in the Managing Indexers and Clusters Manual

Fixed Issues

This version of the Splunk Add-on for VMware has the following reported fixed issues. If no issues appear below, no issues have yet been reported.


Known Issues

This version of the Splunk Add-on for VMware has the following reported known issues and workarounds. If no issues appear below, no issues have yet been reported.


Date filed Issue number Description
2021-08-05 VMW-6236 Incorrect value for Cluster performance metrics due to aggregation mechanism on vCenter side.
2021-06-09 VMW-6165 Drill-down not working in Event viewer panels in Hydra Framework in Splunk 8.2.0,8.2.1
2020-09-30 VMW-5802 No data collection occurs when the DCN is configured with more than 8 worker processes on Splunk version 8.x.
2019-10-11 VMW-5269 Collection configuration page doesn't get loaded in Internet Explorer browser
2019-09-19 VMW-5240 Gaps and negative values in VMware Host/VM Performance data at random time samples
2019-09-19 VMW-5239 Duplication in performance data for random sampling time
2019-06-19 VMW-5134 Field changeset is having value "null" in inventory data
2018-04-25 VMW-4848 DCN collection worker failures - vmodl.query.PropertyCollector:session exceptions.
Last modified on 05 August, 2021
PREVIOUS
About the Splunk Add-on for VMware
  NEXT
Release history for Splunk Add-on for VMware

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters