Splunk® App for Infrastructure (Legacy)

Install and Upgrade Splunk App for Infrastructure

This documentation does not apply to the most recent version of Splunk® App for Infrastructure (Legacy). For documentation on the most recent version, go to the latest release.

Install VMware data collection add-ons and dependencies

Install the VMware data collection add-ons and dependencies to collect and monitor VMware data in the Splunk App for Infrastructure (SAI). You need to install components in the indexer tier. You don't install any components in the search head tier. After you install everything, you have to deploy a Data Collection Node (DCN) and Data Collection Scheduler (DCS) to collect VMware data.

VMware data collection requires a Splunk IT Service Intelligence (ITSI) license. To get all the components to collect VMware data, you have to download the ITSI package from Splunkbase.

To follow these steps, you have to have already configured SAI. If you haven't set up SAI yet, do that first. For information, see one of these topics:

When you're done installing and configuring all the VMware data collection components, deploy a Data Collection Node (DCN) and Data Collection Scheduler (DCS) to configure data collection. For more information, see these topics:

After you deploy a DCN and DCS, use a DCS to schedule data collection jobs for a DCN. For steps about how to collect VMware data, see these topics:

Steps

Before you start, see VMware data collection planning and requirements. Follow these steps to install components for VMware data collection in a standalone or distributed Splunk Enterprise deployment.

1. Download Splunk IT Service Intelligence version

The VMware data collection components come with Splunk IT Service Intelligence (ITSI) from Splunkbase in the vmware_ta_itsi parent directory. These steps don't show you how to install ITSI. You just need to download the ITSI package for the required VMware data collection components you have to install. If you're installing ITSI as well, see the ITSI Install and Upgrade manual.

2. Install SA-VMWIndex, Splunk_TA_esxilogs, and Splunk_TA_vcenter on indexers

Open the vmware_ta_itsi parent directory in the ITSI package and Install SA-VMWIndex, Splunk_TA_esxilogs, and Splunk_TA_vcenter from the directory on every indexer that runs the Splunk Add-on for Infrastructure.

If you're installing VMware data collection components in a non-clustered indexer environment, follow these steps.

  1. On each indexer, copy the SA-VMWIndex, Splunk_TA_esxilogs, and Splunk_TA_vcenter directories from the vmware_ta_itsi parent directory to the $SPLUNK_HOME/etc/apps directory.
  2. Restart Splunk:
    $ cd $SPLUNK_HOME/bin/splunk restart
    

If you're installing VMware data collection components in a clustered indexer environment, follow these steps. For more information about this task, see Update common peer configurations and apps in the Managing Indexers and Clusters of Indexers guide.

  1. On the machine that runs the indexer cluster manager node, copy the SA-VMWIndex, Splunk_TA_esxilogs, and Splunk_TA_vcenter directories from the vmware_ta_itsi parent directory to the $SPLUNK_HOME/etc/master-apps directory.
  2. Validate the bundle and check whether a restart is necessary:
    splunk validate cluster-bundle --check-restart
    
  3. Apply the bundle to the indexer cluster:
    splunk apply cluster-bundle
    
  4. To see how the cluster bundle push is going, run this command:
    splunk show cluster-bundle-status
    
Last modified on 04 August, 2020
VMware data collection planning and requirements   Deploy a Data Collection Node

This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1 Cloud only


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters