Release notes for Splunk Add-on for VMware
Version 4.0.3 of the Splunk Add-on for VMware was released on July 13, 2021.
Version 4.0.3 of Splunk Add-on for VMware only contains Splunk_TA_vmware and SA-Hydra packages. The SA-VMWIndex, TA-VMW-FieldExtractions, Splunk_TA_vcenter, Splunk_TA_esxilogs packages that were part of add-on build in v4.0.2 or below, have been removed from the add-on and are published as individual apps on Splunkbase.
For Version 4.0.3, the Splunk Add-on for VMware is now updated to use jQuery v3.5.0. The add-on uses jQuery v3.5 in the Splunk version 8.2 or later. This makes the add-on more secure by fixing known cross-site scripting (XSS) related vulnerabilities as well as vulnerabilities created by object prototype pollution. The Splunk Add-on for VMware packages now supports self-service installation in cloud environments. The following packages have been removed from the add-on package and published as individual add-ons on Splunkbase to support self-service installation in cloud environments.
|SA-VMWIndex||Splunk Add-on for VMware Indexes||4.0.3|
|TA-VMW-FieldExtractions||Splunk Add-on for VMware Extractions||4.0.3|
|Splunk_TA_esxilogs||Splunk Add-on for VMware ESXi Logs||4.2.1|
|Splunk_TA_vcenter||Splunk Add-on for vCenter Logs||4.2.1|
In the Splunk Add-on for VMware version 4.0.2, occurrences of biased terms such as master, slave, blacklist, and whitelist have been replaced with appropriate non-biased terms. The occurrences of biased terms that are Splunk platform references or present in the third-party library have not been removed.
The Splunk Add-on for VMware version 4.0.1 and Splunk App for VMware version 4.0.1 must be in the same cloud environments. This makes the installation procedure for the Splunk App and Add-on for VMware easier in cloud environments.
Version 3.4.2 of the Splunk Add-on for VMware has a new component SA-VMWIndex, which has all VMware indexes.
Version 3.4.3 of the Splunk Add-on for VMware has a new component TA-VMW-FieldExtractions, which has search time knowledge objects.
Version 3.4.5 of the Splunk Add-on for VMware supports Splunk Enterprise version 7.3.1.
Version 3.4.6 of Splunk Add-on for VMware (except SA-VMNetAppUtils package) provides Python 3 support in Splunk Enterprise. It supports Splunk Enterprise version 8.0.0 in either Python 2 or Python 3 mode (after removing SA-VMNetAppUtils package), 7.3.x, 7.2.x. Also, the collection configuration page of the VMware TA is redesigned to make it compatible with Splunk version 8.0.0.
Version 3.4.7 of the Splunk Add-on for VMware now uses Python 3 interpreter by default on Splunk 8.x, it will use Python 2 for Splunk 7.x versions. Version 3.4.7 of the Splunk Add-on for VMware is FIPS compliant. Also, it does not contain the SA-VMNetAppUtils component, which is now part of the Splunk App for VMware package and is required on Search heads only.
The Splunk Add-on for VMware version 4.0.0 and Splunk App for VMware version 4.0.0 must be in the same cloud environments. This makes the installation procedure for the Splunk App and Add-on for VMware easier in cloud environments.
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
Upgrade from version 4.0.2 to 4.0.3
See the steps to upgrade from the Splunk Add-on for VMware from v4.0.2 to v4.0.3. If you are using a version previous to 4.0.2, follow the steps to upgrade to v4.0.2 first.
Upgrade from versions 3.4.6 and earlier
In the release 3.3.2, the
SA-Utils component has been renamed to
SA-VMNetAppUtils. It does not change the input and dashboard you configured in Splunk Add-on for VMware and Splunk App for VMware.
In the release 3.4.2, a new component,
SA-VMWIndex has been added to the Splunk Add-on for VMware package. This component contains the indexes.conf which has the definitions of all the indexes [vmware-perf, vmware-inv, vmware-taskevent, vmware-vclog, vmware-esxilog]. The indexes.conf will be removed from all the components of VMware Add-on as these have been added to
In the release 3.4.3, a new component,
TA-VMW-FieldExtractions has been added to the Splunk Add-on for VMware package. This component contains the search time knowledge objects. The search time knowledge objects have been removed from
See the upgrade section of the Splunk App for VMware manual for the detailed procedures.
Note: Splunk recommend you backup your existing deployment before upgrade.
See "Back up configuration information" in the Admin Manual and "Back up indexed data" in the Managing Indexers and Clusters Manual
This version of the Splunk Add-on for VMware has the following reported fixed issues. If no issues appear below, no issues have yet been reported.
This version of the Splunk Add-on for VMware has the following reported known issues and workarounds. If no issues appear below, no issues have yet been reported.
|Date filed||Issue number||Description|
|2021-08-05||VMW-6236||Incorrect value for Cluster performance metrics due to aggregation mechanism on vCenter side.|
|2021-06-09||VMW-6165||Drill-down not working in Event viewer panels in Hydra Framework in Splunk 8.2.0,8.2.1|
|2020-09-30||VMW-5802||No data collection occurs when the DCN is configured with more than 8 worker processes on Splunk version 8.x.|
|2019-10-11||VMW-5269||Collection configuration page doesn't get loaded in Internet Explorer browser|
|2019-09-19||VMW-5240||Gaps and negative values in VMware Host/VM Performance data at random time samples|
|2019-09-19||VMW-5239||Duplication in performance data for random sampling time|
|2019-06-19||VMW-5134||Field changeset is having value "null" in inventory data|
|2018-04-25||VMW-4848||DCN collection worker failures - vmodl.query.PropertyCollector:session exceptions.|
About the Splunk Add-on for VMware
Release history for Splunk Add-on for VMware
This documentation applies to the following versions of Splunk® Supported Add-ons: released