Splunk® App for VMware (Legacy)

Installation Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Configure Splunk App for VMware to collect data from vCenter Server

Configure a Data Collection Node

The Distributed Collection Scheduler, on the Splunk search head, manages the Data Collection Nodes (DCNs). Register all data collection nodes with the Distributed Collection Scheduler in order to collect data from vCenter Server. You must configure each DCN separately with the scheduler.

Register a DCN with the scheduler

  1. Log in to Splunk Web on the search head as admin.
  2. From the App menu, select VMware.
  3. From the Settings menu select Collection Configuration, then click +.
  4. Enter the settings for the data collection node, then Click Save.
    • See the Data Collection Node configuration settings table.
    Field Value
    Splunk Forwarder URI The address or port of the DCN. For example, https://<host_name_or_ip_address_of_DCN>:8089.
    Splunk Forwarder Username admin.
    Splunk Forwarder Password The administrator password. Make sure this password is not the Splunk Enterprise default admin password (changeme).
    Worker Processes The number of worker processes must be one fewer than the number of CPU cores the vCenter Server system granted to the DCN. For example, if the DCN has four CPU cores, the number of worker processes is three.
  5. Confirm that you correctly configured the DCN by verifying that the DCN, credential validation, and add-on validation all display a green check.
  6. Repeat the steps for each DCN.

Configure vCenter Server

Add a vCenter Server system as a source of data in your environment.

1. On the Collection Configuration dashboard, in the Virtual Centers panel, click +.

2. Enter the settings for the vCenter Server.

Field Value
Virtual Center FQDN The fully-qualified domain name for the vCenter server. For example, test-vcenter100.example.com
VC Username The username that you configured in vCenter Server for Splunk Enterprise. Use the format username@domain if the user is an Active Directory account.
VC Password The password that you configured in vCenter Server for Splunk Enterprise.


3. For the initial installation, pull 20 or fewer hosts. If the vCenter Server manages other servers, make sure that Collect form all hosts and whitelist-specific hosts are not selected.

4. Click Save.

5. Verify that each of the vCenter Server entries displays a green check.

6. Click Start Scheduler. The Distributed Collection Scheduler is running when the button label is Stop Scheduler.

Test DCN and vCenter Server configurations

1. Approximately ten minutes after you start the scheduler, access the search head and navigate to the Splunk Search field.

2. Type a search string to test data collection.

sourcetype=vmware:perf* OR sourcetype=vmware:inv:hierarchy

3. Confirm that the search returns results. Dashboards and some of the other graphics might take up to 60 minutes to populate.

Last modified on 22 June, 2016
PREVIOUS
Configure the data collection node and system settings
  NEXT
Collect VMware vCenter Server Linux Appliance log data

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters