Splunk® App for VMware (Legacy)

Installation and Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Configure Operating System properties

You can configure operating system properties to improve that stability of your data collection nodes in a production environment. These configuration changes are optional.

Set static IP addresses

You can set a static IP address for the data collection node. DHCP (dynamic addressing) can cause the collection node's IP address to vary over time, which results in unexpected behavior. Making a connection to a specific collection node can become difficult (especially if DNS is down). If you want to connect to the collection node to perform maintenance or to determine which collection node is sending data, setting a status IP address makes connecting to the node easier.

Log in as the splunkadmin user to make changes to the data collection node.

Change the NTP server pool list

The Network Time Protocol (NTP) is used to synchronize a computer's time with another reference time source. Most *Nix systems provide you with the ability to set up or change time synchronization.

You can change the NTP servers that your data collection node uses by editing the /etc/ntp.conf file.

The default values for the servers in /etc/ntp.conf are:

# Use public servers from the pool.ntp.org project.
# Please consider joining the pool (http://www.pool.ntp.org/join.html).
server 0.centos.pool.ntp.org
server 1.centos.pool.ntp.org
server 2.centos.pool.ntp.org

To use different NTP servers, replace the default values in the file with your specific values. Restart ntpd for the changes to take effect.

sudo service ntpd restart

Disable NTP on the data collection node

If you do not have access to the internet you can disable NTP on the data collection node. This can happen when you operate behind a firewall that precludes access to the Internet. If you disable NTP, re-enable VMware Tools Clock Synchronization which gets the data collection node's time from the underlying ESXi host. Log in and execute the following commands as the splunkadmin user:

  1. Stop ntpd service and configure it so that it does not run at system startup:
    sudo service ntpd stop
    sudo chkconfig ntpd off
  2. Enable timesync:
    vmware-toolbox-cmd timesync enable
  3. Check that timesync is enabled correctly:
    vmware-toolbox-cmd timesync status
Last modified on 02 April, 2014
Get a collection node   Install on your search head or indexer

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.0, 3.0.1, 3.0.2, 3.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters