Splunk® App for VMware (Legacy)

Installation Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Platform and hardware requirements

Splunk App for VMware works on Splunk Enterprise deployed in a *nix environment. Windows is not a supported operating system for this app. See "System requirements" in the Splunk Enterprise Installation Manual. The requirements below must be satisfied to install and run the Splunk App for VMware:

Splunk App for VMware Installation Prerequisites

The Installation Guide assumes the following prerequisites:

  • A configured and ready to use Splunk platform environment.
  • A search head that runs on a 64-bit Linux operating system. Your Splunk environment can be a single-instance deployment, or a deployment with a dedicated search head and one or more indexers.
  • A default Splunk Enterprise configuration with a licensing volume that can support approximately 300MB of data per host per day.
  • You are using a supported version of VMware vCenter Server to manage hypervisors. Splunk App for VMware integrates with a vCenter Server and the hypervisors it manages. Environments with Windows-based vCenter and/or Linux-based vCenter Server Appliance are supported. ESXi servers that are not managed through vCenter are not supported.
  • You are using a standard deployment configuration. The Installation Guide describes installing Splunk App for VMware with Data Collection Node (DCN) virtual appliances in their standard configuration. See "Set up a data collection node" in the Configuration Guide to learn how to create a custom DCN.

Component version compatibility

See the table below to identify component version compatibility for your Splunk VMware deployment:

Compatible Splunk platform version Compatible Splunk App for VMWare version Compatible vCenter version Compatible vSphere version Compatible ESXi version Compatible SA-Hydra version Compatible SA-Utils version
6.2.0 and above 3.2.1 and above 5.0 and above 4.1, 5.0, 5.0 Update 1, 5.1, 5.5, 5.5a, 6.0 and above. 4.1, 5.0, 5.0 Update 1, 5.1, 5.5 on 64-bit x86 CPUs, 5.5 update 1 and above. 4.0.2 and above 3.5.0

Additional Considerations:

Scheduler requirements

For single deployments of the VMWare app scheduler, refer to Splunk Enterprise's search head hardware recommendations.

Distributed Collection Scheduler requirements

These supporting add-ons support the Distributed Collection Scheduler in the Splunk App for VMware. They are versioned separately to the Splunk App for VMware. It is important to note the versions installed if you have Splunk App for NetApp ONTAP installed as it also uses the Distributed Collection Scheduler. See "Prepare Splunk App for NetApp Data ONTAP".

  • SA-Hydra version 4.0.2.
  • SA-Utils version 3.5.0.

Supported versions

Splunk App for VMware supports many VMware product versions.

  • VMware vSphere versions 4.1, 5.0, 5.0 Update 1, 5.1, 5.5, 5.5a, and 6.0.
  • ESXi 4.1, 5.0, 5.0 Update 1, 5.1, 5.5 on 64-bit x86 CPUs, and 5.5 Update 1.
  • vCenter Server on a Windows operating system.
  • Linux-based vCenter Server Appliance. Collect API data and syslog data using Splunk App for VMware. You can also collect VMware vCenter Server Linux Appliance log data. See "Set up the Splunk App for VMware to collect log data".

Splunk App for VMware supports vCenter Server systems in Linked Mode. Splunk App for VMware collects API data for vCenter Server systems in a linked pool after you add them to the Collection Configuration dashboard in Splunk App for VMware. Splunk App for VMware does not recognize vCenter Servers in a linked pool that are not included in the data collection configuration.

Supported browsers

  • Mozilla Firefox
  • Microsoft Internet Explorer 9 and 10
  • Apple Safari
  • Google Chrome

Splunk App for VMware does not support Internet Explorer 8 or Internet Explorer 9 Compatibility Mode.

Last modified on 07 July, 2016
Download the Splunk App for VMWare   Plan your installation in a test environment

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.2.0, 3.2.1, 3.2.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters