Collect VMware vCenter Server Linux Appliance log data
Use Splunk App for VMware to collect logs from the VMware vCenter Server Linux Appliance. Splunk App for VMware stores VMware vCenter Server Linux Appliance logs in /var/log/vmware
.
- Export vCenter logs to another system on which you have installed Splunk Enterprise.
- Install a Splunk Enterprise forwarder on the same machine to forward the VMware vCenter Linux appliance logs. See "Forward VMware vCenter Linux appliance logs to Splunk Enterprise".
- Note: You do not need to collect log data from a VMware vCenter Server Linux Appliance in order to see a working version of the Splunk App for VMware.
Export vCenter logs to an external system
- Enable the VMware vCenter Server Appliance to store log files on NFS storage on a system on which you have installed Splunk Enterprise as a heavy forwarder or as a light forwarder. See "Create NFS Datastore in the vSphere Client" in the VMware vSphere documentation.
- On the system on which you have installed the Splunk Enterprise forwarder, install Splunk_TA_vCenter.
- Copy the
inputs.conf
file from$SPLUNK_HOME/etc/Splunk_TA_vCenter/default
then paste it into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder and open file. - Optional If you configured Splunk Enterprise as a heavy forwarder and you want to monitor the license file and and tomcat configuration files, edit the following stanzas in the
props.conf
file:- a. Copy the
$SPLUNK_HOME/etc/Splunk_TA_vCenter/default/props.conf
file, then paste into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder.
- a. Copy the
- Start Splunk Enterprise.
Forward VMware vCenter Linux appliance logs to Splunk Enterprise
To forward VMware vCenter Linux appliance logs to your Splunk Enterprise indexers or search head, install a Splunk Enterprise forwarder on the VMware vCenter Linux appliance. Access to vCSA shell access must be enabled.
- Install a Splunk forwarder on the VMware vCenter Server Appliance. See steps 1 - 3 of Collect Windows VMware vCenter Server logs.
- Install Splunk_TA_vCenter on the Splunk Enterprise forwarder.
- 1. Get the
Splunk_TA_vcenter-<version>-<build_number>.zip
file from the download package and place it on vCenter. - 2. Unzip the Splunk App for VMware package.
cd /opt/splunkforwarder
Splunk_TA_vcenter-<version>-<build_number>.zip"
- 3. Verify that you successfully extracted the
Splunk_TA_vcenter/…
in the$SPLUNK_HOME/etc/apps
directory.
- 1. Get the
- Copy the
inputs.conf
file from$SPLUNK_HOME/etc/Splunk_TA_vCenter/default
then paste it into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder and open file. - Start your Splunk Universal Forwarder.
Configure Splunk App for VMware to collect data from vCenter Server | Troubleshoot Splunk App for VMware |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2
Feedback submitted, thanks!