Splunk® App for VMware (Legacy)

Installation and Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Launch Splunk Web

You now have Splunk for VMware installed in your environment. You have it configured to collect data from the VMware resources you designated. The next step is to validate that you are collecting all the data you want and that the data is correct.

To check that the solution was installed correctly and that you are collecting the correct data from the correct resources, you can look at the dashboards in the Splunk App for VMware.

To do this:

  1. Check that Splunk is running in your environment.
  2. Open a browser and log into Splunk Web on your indexer/search head. Use the host and port you chose during installation. The default port is 8000 of the host on which it's installed. If you are using Splunk on your local machine, the URL to access Splunk Web is http://localhost:8000.
  3. Log in to the Splunk instance (the default login is username=admin/password=changeme).
  4. If you are using an Enterprise license, launching Splunk for the first time takes you to this login screen. Follow the message to authenticate with the default credentials:
    First time login.png
  5. When you sign in with your default password, Splunk asks you to create a new password. You can either Skip this or change your password to continue.
    Password prompt.png
    If you are using a Free license, you do not need to authenticate to use Splunk. In this case, when you start up Splunk you won't see this login screen. Instead, you will be taken directly to Splunk Home or the default App for your account.
  6. In Splunk Home, select the Splunk App for VMware. Mapping the data from Splunk to the dashboards and views in the App can take a few minutes.
    VMware home.png
  7. Look at the App Install health view and check that you are running the correct versions of the software and that the views are populated with the correct data. If the data does not display correctly in the dashboards you can examine your inputs.conf file for errors. How quickly the views are populated with data depends on the amount of data coming into Splunk. Populating the dashboards can take some time.

Check the App Install health dashboard

The App Install health dashboard in the App provides information about what you installed into your environment and how your environment is configured to collect data and bring it into Splunk. Examine each of the panels on this dashboard. Always check inventory, hierarchy, time, performance, and log data in the App for the given vCenter and associated ESX/i hosts.

In the Sourcetypes last received status view, check the recent index time and the recent sent time to see if your FA or any of your ESX/i servers show up with an unacceptable time difference. If some do not, the clock on that host is most likely set incorrectly. If the time is set incorrectly, you must fix the time on all of your hosts for the solution to work correctly. If you had to reset the time on your FA, restart the forwarder inside it, wait for a few minutes, and then verify once again that the time difference you are seeing is within an acceptable time range.

When you have verified the time for the FA and all of your ESX/i hosts, you can then check to see that all of the different kinds of data in the solution are being captured correctly. See Is data coming in to learn more about how to check that the data you are collecting is of the correct type.

It can take time for the views to populate especially if you have a large environment collecting many different types of data. Give the dashboards some time to load the data before you start troubleshooting.

Last modified on 22 January, 2013
Obfuscate passwords   Is data coming in

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 2.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters