Splunk® IT Service Intelligence

Modules

Download manual as PDF

Download topic as PDF

Storage Module configuration

Module entity roles

See the below table to identify the roles that the Splunk ITSI Storage Module assigns to entities:

ITSI Module ITSI Roles
ITSI Storage Module storagesystem

Step 1: Install supported technologies

Install your ITSI supported technologies onto your deployment using the reference table below. For single-instance deployments, install all supported technologies on your single instance.

Technology Name Installation link Search Heads Indexers Forwarders
Splunk Add-on for NetApp Data ONTAP Installation guide x x x
Splunk Add-on for EMC VNX Installation guide x x x

See About installing Splunk add-ons to learn how to install a Splunk add-on in the following deployment scenarios.

Step 2: Configure supported technologies

Configure the Splunk Add-on for EMC VNX

  1. Configure the modular input for the Splunk Add-on for EMC VNX
  2. Configure the collection interval for the Splunk Add-on for EMC VNX

Configure the Splunk Add-on for NetApp DATA ONTAP to send data to your ITSI deployment

  1. Configure the Splunk Add-on for NetApp DATA ONTAP
  2. Add a data collection node
    1. Navigate to the version of the Splunk Add-on for NetApp Data ONTAP that is installed on your Splunk platform deployment, and click Collection Configuration.
    2. Under Under Data Collection Nodes, select Add Data Collection Node.
    3. Enter in your Splunk Forwarder URI, Username, Password, and number of Worker Processes.
    4. Click Save.
  3. Add an ONTAP collection
    1. On the ONTAP Collection Configuration page, select Add ONTAP Collection.
    2. Deselect the Use Realm Based Credentials checkbox.
    3. Enter in your ONTAP Servers IP:MGMT_Port, ONTAP Username, ONTAP Password and check the Collect All Performance Categories checkbox.
    4. (Optional) Select the Use Realm Based Credentials checkbox and enter Realm credentials.
    5. Click Save.

Step 3: Add roles to admin user

itoa_admin is the admin role for ITSI. It should have access to indexes of apps that you want to monitor in ITSI.

  1. Navigate to Settings and click Access Control under Users and Authentication.
  2. Click Roles
  3. Click itoa_admin
  4. Under Inheritance > Available roles, click on splunk_ontap_admin and splunk_ontap_user to move them to Selected roles.
  5. Under Indexes searched by default, select the index that you specified during Splunk Add-on for EMC VNX Configuration to move it to Selected indexes
  6. Click Save

Configure ITOA roles to access Splunk Add-on for VMWare data within ITSI

The Splunk Add-on for VMware creates roles called splunk_vmware_user splunk_vmware_admin within the Splunk platform. Configure and assign the appropriate ITOA role to existing users or groups of users to grant them access to the Splunk Add-on for VMware data within ITSI.

  1. Log in to your Splunk search head.
  2. Navigate to Settings > Access controls > Users.
  3. Assign the splunk_vmware_admin to the ITOA_admin role of your Splunk platform instance. Users with the administrator role can configure data collection or thresholds for Splunk App for VMware.
  4. Assign the splunk_vmware_user roles to the ITOA_user role of your Splunk platform instance.
  5. Save your changes.

Step 4: Verify Data Collection

Verify that the add-ons in your deployment are installed and configured correctly by checking the add-on's indices, sources or source types.

Supported technology Data verification search
Splunk Add-on for NetApp Data ONTAP tag=storagesystemindex=ontap
Splunk Add-on for EMC VNX tag=storagesystem OR index=<Specified during TA Configuration>

Step 5: Enable entity discovery

Enable entity discovery for the module to automatically discover entities for which relevant data has been collected. See Enable the automatic entity discovery search.

Last modified on 13 March, 2020
PREVIOUS
About the ITSI Module for Storage Array Monitoring
  NEXT
Storage Module KPIs and thresholds

This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.0, 4.1.1, 4.1.2, 4.1.5, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.4.0, 4.4.1, 4.4.2, 4.4.3


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters