Splunk® App for VMware (Legacy)

Installation Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Collect VMware vCenter Server Linux Appliance log data

The Splunk App for VMware uses the Splunk Add-on for VMware to collect logs from the VMware vCenter Server Linux Appliance. The Splunk Add-on for VMware stores VMware vCenter Server Linux Appliance logs in /var/log/vmware.

See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to collect VMware vCenter Server Linux Appliance log data.

Export vCenter logs to an external system

Enable the VMware vCenter Server Appliance to store log files on NFS storage on a system on which you have installed Splunk Enterprise as a heavy forwarder or as a light forwarder. See the "Create NFS Datastore in the vSphere Client" in the VMware vSphere documentation.

See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to export vCenter logs to an external system.

Forward VMware vCenter Linux appliance logs to Splunk Enterprise

To forward VMware vCenter Linux appliance logs to your Splunk Enterprise indexers or search head, install a Splunk Enterprise forwarder on the VMware vCenter Linux appliance. Access to vCSA shell access must be enabled.

See the Configure the Splunk Add-on for VMware to collect data section of the Splunk Add-on for VMware manual to export vCenter logs to forward VMware vCenter Linux appliance logs to Splunk Enterprise.

Last modified on 12 October, 2017
Collect data from vCenter Server   Troubleshoot Splunk App for VMware

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.4.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters