Splunk® App for VMware

User Guide

Download manual as PDF

This documentation does not apply to the most recent version of VMW. Click here for the latest version.
Download topic as PDF

Common use cases

Use the Splunk App for VMware to get a greater understanding of what is happening at the operational level in your VMware vSphere environment. Some use cases for the app are described in this topic.

Use case Description
Inventory monitoring The Splunk App for VMware collects inventory data that enables you to better monitor the components in your VMware vSphere environment. These inventory objects include hosts, virtual machines, data stores, and networks.
Performance monitoring All of the dashboards in the Splunk App for VMware display a real-time operational state of the entities in your vSphere environment based on thresholds that are predefined in the Splunk App for VMware.

In addition to reporting on VMware performance, you can:

  • Look at host details and compare hosts in your environment.
  • Monitor real-time dashboards that visualize performance events across the virtual topology map.
  • Drill down to problem sources and access granular performance metrics using accelerated Splunk Enterprise searches.
  • Proactively detect performance issues and prevent them from impacting your end users.
Correlation The Splunk App for VMware gathers granular performance and event data from your virtualization layer. Correlate that data with data from other entities (such as datastores) to resolve issues in your environment.
Troubleshooting Use the dashboards in the Splunk App for VMware to determine the root cause of performance problems in your environment.
  • Navigate the topology map in the Proactive Monitoring view and drill down to discover the source of problems in your environment.
  • Track migrating virtual machines in your environment (as they migrate from one physical host to the next).
Scaling The Proactive Monitoring view builds an interactive topology map of you environment. It is designed to scale to the largest of virtual environments and provides quick access to the data.
Capacity planning and reporting Use the dashboards to find resources that are over or under utilized in your virtual infrastructure.
  • See real-time data for cpu, memory, disk, and datastore consumption and optimize your environment based on consumer needs.
  • Set alerts to notify you when capacity shortfalls occur and see where you can reclaim unused space or re-allocate additional resources.
  • Get visibility into bottlenecks and capacity utilization. The Splunk App for VMware collects granular performance metrics at 20-second intervals which enables you to trend utilization over time and optimize based on your data.
  • Use capacity forecasting to predict resource usage for different entities in your environment.
Proactive (operational) monitoring Use the searches and reports to track changes in your environment.
  • Use the interactive visual maps of your virtual environment and alert on abnormalities to proactively manage issues.
  • Look at the real-time operational state (Home view) based on predefined thresholds and drill down into an interactive topology map to isolate problems.
Security reporting Look at a visual display of security relevant events and check for potential security breaches.
  • Get visibility into user activity using access controls and an audit of tasks and events on your virtual infrastructure.
Change tracking Audit changes to your environment, manage users and roles, and get insight to the scope and impact of changes that can negatively affect availability, performance, security and capacity.
  • Keep track of your virtual infrastructure, the state of the assets, and trend the performance impact of migrating virtual machines (from host to host).
  • Monitor events to get a definitive record of what happened in your environment.
  • Explore the topology map of your virtual environments. Highlight problems and make comparisons based on performance metrics.
Last modified on 22 June, 2016
PREVIOUS
App Data Volume
  NEXT
Reports

This documentation applies to the following versions of Splunk® App for VMware: 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters