Collect VMware vCenter Server Linux Appliance log data
Use Splunk App for VMware with the Splunk Add-on for VMware to collect logs from the VMware vCenter Server Linux Appliance. The Splunk Add-on for VMware stores VMware vCenter Server Linux Appliance logs in /var/log/vmware
.
- Export vCenter logs to another system on which you have installed Splunk Enterprise.
- Install a Splunk Enterprise forwarder on the same machine to forward the VMware vCenter Linux appliance logs. See Forward VMware vCenter Linux appliance logs to Splunk Enterprise.
- You do not need to collect log data from a VMware vCenter Server Linux Appliance in order to see a working version of the Splunk App for VMware.
Export vCenter logs to an external system
- Enable the VMware vCenter Server Appliance to store log files on NFS storage on a system on which you have installed Splunk Enterprise as a heavy forwarder or as a light forwarder. See the "Create NFS Datastore in the vSphere Client" in the VMware vSphere documentation.
- On the system on which you have installed the Splunk Enterprise forwarder, install
Splunk_TA_vCenter
. - Copy the
inputs.conf
file from$SPLUNK_HOME/etc/Splunk_TA_vCenter/default
then paste it into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder and open file. - Optional If you configured Splunk Enterprise as a heavy forwarder and you want to monitor the license file and and tomcat configuration files, edit the following stanzas in the
props.conf
file:- a. Copy the
$SPLUNK_HOME/etc/Splunk_TA_vCenter/default/props.conf
file, then paste into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder.
- a. Copy the
- Start Splunk Enterprise.
Forward VMware vCenter Linux appliance logs to Splunk Enterprise
To forward VMware vCenter Linux appliance logs to your Splunk Enterprise indexers or search head, install a Splunk Enterprise forwarder on the VMware vCenter Linux appliance. Access to vCSA shell access must be enabled.
- Install a Splunk forwarder on the VMware vCenter Server Appliance.
- Install Splunk_TA_vCenter on the Splunk Enterprise forwarder.
- Get the
Splunk_TA_vcenter-<version>-<build_number>.zip
file from the download package and place it on vCenter. - Unzip the Splunk App for VMware package.
cd /opt/splunkforwarder
Splunk_TA_vcenter-<version>-<build_number>.zip
- Verify that you extracted the
Splunk_TA_vcenter/…
in the$SPLUNK_HOME/etc/apps
directory.
- Get the
- Copy the
inputs.conf
file from$SPLUNK_HOME/etc/Splunk_TA_vCenter/default
then paste it into the$SPLUNK_HOME/etc/Splunk_TA_vCenter/local
folder and open file. - Start your Splunk Universal Forwarder.
Configure Splunk App for VMware to collect data from vCenter Server | Troubleshoot Splunk App for VMware |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.3.1
Feedback submitted, thanks!