Splunk® App for VMware (Legacy)

User Guide

On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.

Useful Saved Searches

Use these searches to help troubleshoot problems with network connectivity.

You can:

  • Edit the search and save it as a report, a dashboard panel, an alert, or an event type.
  • Edit the description and the permissions for the search.
  • Schedule the search.
  • Add the search to a dashboard.

Useful saved search description

Name Search Description
vProb errors in logs sourcetype="vmware:*log*" error "vProb*" Detects network problems with storage devices.
vmfs volume locked sourcetype="vmware:*log*" vmfs volume locked Detects if a volume is locked by another host.
vCenter starts `VcLogSourcetypes` "Starting * VirtualCenter" Detects if there are problems starting the vCenter server.
All paths are dead sourcetype="vmware:*log*" "APD" Detects if a storage device was removed from an ESX/i host in an uncontrolled manner.
SCSI reservation error-i/o failed sourcetype="vmware:*log*" "SCSI reservation error - i/o failed" Detects the virtual machines experiencing I/O failures due to too many SCSI reservation conflicts.
Lost Connectivity sourcetype="vmware:*log*" "Lost connectivity" Detects loss of connectivity between vSphere and a device.
Duplicate IPs sourcetype=vmware:esx*:* "duplicate IP" Detects if duplicate IP addresses exists in the VMware ESX/i logs.
Last modified on 22 October, 2021
Security Overview   Threshold Configuration

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.7, 4.0.0, 4.0.1, 4.0.3


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters