Collect Windows vCenter log data
Install the Splunk Technology Add-on for VMware vCenter to collect vCenter log data. Use a Splunk Universal Forwarder to forward the log data from your Windows vCenter Server to the Indexer.
- Install a Splunk forwarder.
- Download the Universal Forwarder version you need.
- Install the Universal Forwarder. See "Install a Universal Forwarder on Windows" in the Forwarding Data Manual.
- Configure forwarding.
- Configure the forwarder on your vCenter machines to send data to your indexer(s). Do this in the
outputs.conf
file for each forwarder installed on a vCenter machine. See "Configure forwarders with outputs.conf" in the Forwarding Data Manual.
- Configure the forwarder on your vCenter machines to send data to your indexer(s). Do this in the
- Change your Splunk password.
- The default password for the Splunk Enterprise admin user (on all Splunk instances) is
changeme
. We recommend that you change the password using Splunk Web (https://<ip-address>:8000). See "Change the admin default password" in the Admin manual.
- The default password for the Splunk Enterprise admin user (on all Splunk instances) is
- Install Splunk_TA_vcenter.
- Get the file
Splunk_TA_vcenter-<version>-<build_number>.zip
from the download package and install it on your VMware vCenter machines. - Unzip the file,
"Splunk_TA_vcenter-<version>-<build_number>.zip"
, into theapps
directory under%SPLUNK_HOME%\etc\apps
. When installing on a universal forwarder the path isC:\Program Files\SplunkUniversalForwarder\etc\apps
otherwise it isC:\Program Files\Splunk\etc\apps
.
- Get the file
- Restart Splunk. See "Start and stop Splunk" in the Admin Manual.
- In
%SPLUNK_HOME%\bin
run the commandsplunk restart
. You can also use Windows services and select Start > Administrative Tools > Services > Splunkd restart.
- In
You have now configured the Splunk App for VMware to collect log data from your Windows vCenter servers and to forward the data from vCenter to your Splunk Indexers or combined Indexer Search Head(s).
Configure Splunk for ESXi logs | Collect VMware vCenter Server Linux Appliance log data |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.0, 3.0.1, 3.0.2, 3.1
Feedback submitted, thanks!