Install the App
Install the App on each Splunk indexer and search head in your environment using the same user account that you used to install Splunk on your systems.
Before you install the App you must have:
- Splunk indexers or search heads installed on one or more systems in your environment.
- Splunk App for VMware downloaded from Splunkbase to a location in your environment.
To install Splunk App for VMware
- Transfer the App package file
splunk_app_vmware-<version>-<build_number>.zip
to a temporary location on each indexer and search head in your environment. Create a temporary directory, for example/tmp
on *nix machines orC:\Windows\Temp
on Windows machines. - Unzip the App package in the temporary directory. This creates a new
"etc"
directory.unzip splunk_app_vmware-<version>-<build_number>.zip
To install the App on each dedicated indexer in your environment:
- If you are running both search heads and indexers on the same Splunk instance, Go to the next section "To install the App on each search head (or combined indexer and search head) in your environment:"
- Copy all of the apps in the
etc/deployment-apps
folder onto each of the indexers. ($SPLUNK_HOME/etc/apps
). Use recursive copy to copy all of the files and all of the sub-directories.:etc/
apps/deployment-apps/
Splunk_TA_vcenter/…
Splunk_TA_vmware/…
- Look in
$SPLUNK_HOME/etc/apps
and verify that all of the apps were copied correctly. - Go to
$SPLUNK_HOME/etc/apps/Splunk_TA_vcenter/default
. - Look at your
inputs.conf
file and check that it is set up as follows:- [script://.\bin\SetHost.bat]
- disabled = true
- Restart Splunk on each indexer. For both Windows and Unix instructions, see "Start and stop Spunk" in the Splunk Admin Manual.
- Now that the App is installed you must configure each of your Splunk indexers to listen for data on a (forwarding / receiving) port. See "Set up receiving" in the Splunk product documentation.
To install the App on each search head (or combined indexer and search head) in your environment:
- Copy the contents of the
apps
directory in the temporaryetc/apps
folder into theapps
directory of your Splunk install ($SPLUNK_HOME/etc/apps
). Use recursive copy to copy all of the files and all of the sub-directories.etc/
apps/
SA-Utils/…
SA-Threshold/…
SA-VMW-HierarchyInventory/…
SA-VMW-LogEventTask/…
SA-VMW-Performance/…
Splunk_TA_vcenter/…
Splunk_TA_vmware/…
splunk_for_vmware/…
- Look in
$SPLUNK_HOME/etc/apps
to verify that all apps were copied correctly. - Restart Splunk. For both Windows and Unix instructions, see "Start and stop Spunk" in the Splunk Admin Manual.
- Log into Splunk Web on the search head.
- Open a browser and enter the IP address and port number of the OS hosting your search head: http://<ipaddress:8000/>
- The Splunk Home page is displayed showing all installed apps. Select Splunk App for VMware from the list. The app is also available from the App menu on the Home screen.
- If this is a first time install, you are automatically redirected to the Setup page. Complete the details and continue.
- Click save on the Setup page.
- Now that the App is installed you must configure each of your Splunk indexers to listen for data on a (forwarding / receiving) port. See "Set up receiving" in the Splunk product documentation.
Spunk is almost ready to receive VMware environment data. You must configure your indexers to handle vCenter Server log files. For more information, see Set the timezone for vCenter log files in this manual.
Install UF or LF on each vCenter machine | About the Add-on |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 2.0
Feedback submitted, thanks!