Splunk® App for VMware (Legacy)

Installation Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Plan your installation in a test environment

Install the Splunk App for VMware into a test environment before you install it in a production environment. This way you can work out the complexities and issues that you might encounter in your deployment.

After you install the Splunk App for VMware in your test environment, scale the deployment with more advanced Splunk Enterprise deployment features, such as search head pooling and indexer clustering. See Splunk App for VMware component reference for an overview.

If you do not have access to a test environment, limit the number of hosts and vCenter Servers you use when you first deploy the app, and then add complexity after your initial setup is successful.

Splunk App for VMware sample test environment

Splunk recommends the following test environment size:

  • One vCenter Server that supports 40 or fewer ESXi hosts.
  • One instance of Splunk Enterprise with one search head and one indexer. See Platform and hardware requirements for Splunk Enterprise versions that support Splunk App for VMware.
  • One Data Collection Node (DCN).

In your test environment, deploy the DCN using the configured Splunk OVA to collect vCenter Server API data. See "Deploy OVA to create a Data Collection Node". With the following specifications, one data collection node can collect from 40 ESXi hosts or fewer, with a ratio of 25 to 30 virtual machines per host. The default virtual machine included with the Splunk App for VMware is set with this configuration.

  • Four cores. Four vCPUs or two vCPUs with two cores with a reservation of 2GHz
  • 6GB memory with a reservation of 1GB
  • 10-12GB of disk space

Optionally, you can set up a syslog collector when you install and configure Splunk App for VMware. This action is not required for evaluation and provides minimal additional functionality. See Configure Splunk to receive syslog data.

For information about configuring Splunk App for VMware with other Splunk apps, see Requirements for installing the Splunk App for VMware with other Splunk apps.

Last modified on 22 June, 2016
PREVIOUS
Platform and hardware requirements
  NEXT
Set up a vCenter Server user account

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.2.1, 3.2.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters