Collect VMware vCenter Server Linux Appliance log data
The Splunk App for VMware uses the Splunk Add-on for VMware to collect logs from the VMware vCenter Server Linux Appliance. The Splunk Add-on for VMware stores VMware vCenter Server Linux Appliance logs in /var/log/vmware
.
See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to collect VMware vCenter Server Linux Appliance log data.
Export vCenter logs to an external system
Enable the VMware vCenter Server Appliance to store log files on NFS storage on a system on which you have installed Splunk Enterprise as a heavy forwarder or as a light forwarder. See the "Create NFS Datastore in the vSphere Client" in the VMware vSphere documentation.
See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to export vCenter logs to an external system.
Forward VMware vCenter Linux appliance logs to Splunk Enterprise
To forward VMware vCenter Linux appliance logs to your Splunk Enterprise indexers or search head, install a Splunk Enterprise forwarder on the VMware vCenter Linux appliance. Access to vCSA shell access must be enabled.
See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to export vCenter logs to forward VMware vCenter Linux appliance logs to Splunk Enterprise.
Collect data from vCenter Server | Troubleshoot Splunk App for VMware |
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.4.0
Feedback submitted, thanks!