Splunk® App for VMware (Legacy)

Installation Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Installation overview

Installation of the Splunk OVA for VMware and Splunk Add-on for VMware are prerequisites for the Splunk App for VMware.

Splunk App for VMware package contents

The Splunk App for VMware contains the following components:

  • SA-Threshold
  • SA-VMware HierarchyInventory
  • SA-VMware LogEventTask
  • SA-VMW Performance
  • Splunk for VMware

Install components

The table shows where to install the individual components of Splunk App for VMWare in your distributed environment.

Component Search head Scheduler Indexer Data Collection Node (DCN) ESXi log forwarder vCenter log forwarder
Splunk_for_vmware x
Splunk_TA_vmware x x x x
Splunk_TA_esxilogs x x x
Splunk_TA_vcenter x x x
SA-VMW-HierarchyInventory x
SA-VMW-LogEventTask x
SA-VMW-Performance x
SA-Hydra x x x
SA-Utils x x x
SA-Threshold x

SA-Hydra, SA-Util, Splunk_TA_Vmware, Splunk_TA_esxilogs, and Splunk_TA_vcenter are contained in the Splunk Add-on for VMware package on Splunkbase.

Forwarding vCenter application logs to syslog, an intermediate forwarder, or directly to a Splunk indexer is supported for 6.0 and 5.X versions of vCenter server. As of vCenter 6.0, installing a forwarder on your vCenter server for log forwarding is not necessary or recommended.

The installation of SA-Utils on your license server is optional if your Splunk platform deployment does not use a license server. If your search head handles licensing then SA-Utils should already be installed on your search head.

Component reference

Refer to this table to see the Splunk App for VMware components that are installed and where the components get installed in the Splunk Enterprise and VMware infrastructure.

Component name Description
Scheduler Manages jobs. If you use SHC in your Splunk platform environment, run the scheduler on a separate machine from your SHC members.
Search head If you have a dedicated search head, install all of the components on it. Install SA-Hydra and SA-utils on distributed deployments. Installation of all components on the search head lets you view a complete working version of the app.
Indexer Install all TA components on a dedicated indexer.
Data Collection Node The data collection node OVA ships with all components installed. To build your own data collection node, see create your own data collection node Splunk OVA for VMware.
Esxi host Install the log forwarding technology on the ESXi host. If you use an intermediate heavy forwarder to forward logs, install Splunk_TA_esxilogs on the forwarder.
vCenter server If you use a universal forwarder or light forwarder to forward vCenter logs, install TA_vcenter on it as it contains scripts that configure the inputs.conf.
License Master See "Configure a license master" in the Splunk Enterprise admin manual.
Last modified on 27 October, 2016
Prepare Splunk App for NetApp Data ONTAP   Install the Splunk App for VMware

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters