Splunk® IT Essentials Work

Entity Integrations Manual

This documentation does not apply to the most recent version of Splunk® IT Essentials Work. For documentation on the most recent version, go to the latest release.

About the VMware vSphere entity integration in ITE Work

To collect VMware data in (ITE Work), you need to install the Splunk Add-on for VMware Metrics. The add-on uses a Data Collection Scheduler (DCS) to collect metrics. A DCS schedules data collection jobs for Data Collection Nodes (DCN). DCNs are modified heavy forwarders that collect data from a vCenter Server. You can deploy a DCN with the Splunk OVA for VMware Metrics or as a heavy forwarder that you modify manually.

For more information about the OVA for VMware Metrics, see About the Splunk OVA for VMware Metrics. For more information about the VMware metrics add-on, see About the Splunk Add-on for VMware Metrics.

The VMware vSphere entity integration supports the following entity types:

Install the add-on and data collection components

Before you can start configuring data collection for VMware vCenter servers, you have to install additional components in your environment, deploy a data collection scheduler (DCS), and deploy at least one data collection node (DCN) for each vCenter Server you want to monitor. A single DCS can schedule data collection jobs for multiple DCNs. For information about scaling DCNs for vCenter Servers, see Data Collection Node requirements. The easiest way to deploy a DCN is to use the OVA template. You can also modify a heavy forwarder to perform as a DCN.

You also need to confirm that the proper ports are available and open in your Splunk and vCenter Server environments. To view all the VMware data collection requirements, see Data collection planning and requirements for the Splunk Add-on for VMware Metrics.

View these topics to install the required components, deploy a DCN, and deploy a DCS:

For information about the sources the VMware add-on collects data from, as well as a list of the entities and default dimensions in the performance data, see Source types for the Splunk Add-on for VMware Metrics in the

After you deploy a DCN and a DCS, and deploy the Splunk Add-on for VMware Metrics on your indexers and search head, you can start configuring VMware vCenter Server integrations. For instructions, see Add configurations in the Collection Configuration page of the Splunk Add-on for VMware Metrics.

To collect VMware vCenter Server and ESXI host log data, performance metrics, inventory, and tasks, see Configure Splunk Add-on for VMware Metrics to collect data.

Collect VMware datastore performance metrics

ITE Work contains a saved search that collects VMware datastore entities into ITE Work. Therefore, in addition to installing and configuring the Splunk Add-on for VMware Metrics, you also need to enable the saved search in order for VMware datastore collection to work.

The VMware datastore integration requires the Splunk Add-on for VMware Metrics version 4.1.0 or later, which includes the ability to ingest performance data for VMware datastore metrics into the metrics index. For upgrade steps, see Upgrade the Splunk Add-on for VMware Metrics.

Perform the following steps to collect VMware datastore data in ITE Work:

  1. Install the Splunk Add-on for VMware Metrics version 4.1.0 or later as described in the previous section.
  2. On the ITE Work search head, go to Settings > Searches, reports, and alerts.
  3. Change the Owner to All.
  4. Locate the search named ITSI Import Objects - VMware Datastore.
  5. In the Actions column, click Edit > Enable to enable the search.
  6. Navigate back to the entities lister page in ITE Work and confirm your datastore entities show up and have the entity type VMware Datastore.

Troubleshooting

If you have problems setting up the VMware entity integration, see Troubleshoot the VMware vSphere entity integration in ITE Work.

Last modified on 28 February, 2024
Troubleshoot the Windows entity integration in ITE Work   Troubleshoot the VMware vSphere entity integration in ITE Work

This documentation applies to the following versions of Splunk® IT Essentials Work: 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.10.0 Cloud only, 4.10.1 Cloud only, 4.10.2 Cloud only, 4.10.3 Cloud only, 4.10.4 Cloud only, 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.11.6, 4.12.0 Cloud only, 4.12.2 Cloud only, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.14.0 Cloud only, 4.14.1 Cloud only, 4.14.2 Cloud only, 4.15.0, 4.15.1, 4.15.2, 4.15.3, 4.16.0 Cloud only, 4.17.0, 4.17.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters