Platform and hardware requirements
Splunk Enterprise requirements
- Splunk App for NetApp Data ONTAP works on Splunk Enterprise deployed in a Linux x64 environment. See "System requirements" in the Splunk Enterprise Installation Manual.
- Splunk Enterprise 7.1.0 or later
- A valid Splunk Enterprise license that supports approximately 300 MB to 1GB of data per filer per day.
- A Splunk Enterprise server or forwarder with network access to the NetApp storage controllers.
Distributed Collection Scheduler requirements
These supporting add-ons support the Distributed Collection Scheduler in the Splunk App for NetApp Data ONTAP. See "Other deployment considerations" in this manual.
- SA-Hydra version 4.0.9
- SA-VMNetAppUtils version 1.0.5
Supported NetApp versions
The following table displays the version of the Splunk App for NetApp ONTAP app that have been tested and proven to be compatible with the below versions of the ONTAP line of products.
|Splunk App for NetApp Data ONTAP version||Splunk Add-on for NetApp Data ONTAP version||Splunk Enterprise version||NetApp® Data ONTAP® 7-Mode version||NetApp® Data ONTAP® Cluster Mode version|
|2.1.91||2.1.91||7.1.0 through 7.3.0||up to 8.3||up to 9.4|
Splunk Enterprise supports NetApp® DATA ONTAP on NetApp V-series and FAS controllers.
Splunk App for NetApp Data ONTAP supports the browser versions listed below:
- Firefox (latest)
- Internet Explorer 9 and 10
- Safari (latest)
- Chrome (latest)
Splunk App for NetApp Data ONTAP data volume requirements
Splunk App for NetApp Data ONTAP requires a license that can collect:
- performance data at a volume of 300MB to 1GB per filer per day
- syslog data at a volume of 100MB
The number of volumes and disks in your NetApp environment directly impact your data volume.
When you have the app up and running, navigate to the App Data Volume view to see the volume of data it is indexing in your environment. From the App menu, select Settings, then App Data Volume. You can see:
- The total quantity of data indexed over a 24 hour time period
- A breakdown of the type of data, and the volume of each type
Splunk data collection node resource requirements
At a minimum, a single data collection node requires:
- 4 cores - 4 vCPUs or 2 vCPUs with 2 cores with a reservation of 2 GHz
- 6GB memory with a reservation of 1 GB
- 4-10 GB of disk space
At these requirements, one data collection node can collect from 20 filers.
DCN Software requirements
A single data collection node requires:
- A version of CentOS or RedHat Enterprise Linux (RHEL) that is compatible with one of the following:
- Splunk Enterprise 7.1.0 or later
- A Splunk Enterprise heavy forwarder or light forwarder, version 7.1.0 or later. This is a minimum Splunk requirement for the Splunk App for NetApp Data ONTAP. You cannot use a universal forwarder.
- The following components that are included in the Splunk Add-on for NetApp Data ONTAP:
Detailed logging is implemented as part of the scheduler management and process management. You can set individual logging levels. All of these logs go to
Increased or decreased demand in data collection is met by increasing or decreasing the number of data collection node in your environment and/or increasing or decreasing the number of worker processes per data collection node. Splunk Inc. recommends deploying an additional data collection node for every 20 storage controllers (filers) that you add to your deployment. Maintaining a 1:20 DCN-to-storage controller ratio will help your deployment maintain scalability.
New to Splunk
What data the Splunk App for NetApp Data ONTAP collects
This documentation applies to the following versions of Splunk® App for NetApp Data ONTAP (Legacy): 2.1.91