Splunk® App for VMware (Legacy)

Configuration Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Change data collection node capabilities and log levels

Change DCN capabilities

At the node level, hydra_node.conf contains the capabilities field. The Distributed Collection Scheduler sets the capabilities of the workers on the data collection nodes. You can change the capabilities for a node.

The capabilities in hydra_node.conf can be changed by the data collection node to only include certain tasks. For example, if two data collection nodes are specified in hydra_node.conf, one data collection node can require more power and more memory to process more intensive tasks than the other data collection node. The capabilities are specified by the following lines in hydra_node.conf:

[dcn1:8089]
capabilities = hostinv, vminv
[dcn2:8089]
capabilities = task, event
  1. Create a local version of hydra_node.conf.
  2. Edit $SPLUNK_HOME/etc/apps/Splunk_TA_vmware/local/hydra_node.conf on the scheduler node to adjust the capabilities.
[default]

gateway_port = 8008

capabilities = * 


Change DCN log levels

To troubleshoot your environment, you can set the field worker_log_level in hydra_node.conf for a data collection node.

  1. On the Distributed Collection Scheduler (DCS), create a local version of hydra_node.conf
  1. Edit $SPLUNK_HOME/etc/apps/local/hydra_node.conf to set the log level of for all data collection nodes. The default log level for a data collection node is INFO. The most verbose logging level is DEBUG.

Example:

[default]

gateway_port = 8008

capabilities = * 

log_level = DEBUG
Last modified on 07 February, 2017
Configure performance data collection   Add, edit, and delete threshold settings

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters