Splunk® App for VMware

User Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
Acrobat logo Download topic as PDF

User roles

Role-Based Access Control

The Splunk App for VMware provides role‐based access control. Two roles are defined to provide operators and administrators of the Splunk App for VMware with the specific access each needs.

The default role settings are specified in $SPLUNKHOME/etc/apps/splunk_TA_vmware/default/authorize.conf

The following two roles are defined:

Role Description
splunk_vmware_user Select the user role to assign a permission level for operators of the app who manage virtual environments. As a user you are interested in looking at the data in the dashboards.
splunk_vmware_admin Select the admin role to assign a permission level for administrators of the app who are responsible for installing the app and configuring it to collect data from your virtual environment.

The following table lists the dashboards that each role can access in the Splunk App for VMware:

Dashboard User role Admin role
Home x x
Search x x
Knowledge objects (reports and dashboards) x x
Proactive Monitoring and Entity views x x
Performance and capacity planning views x x
Troubleshooting and security x x
Threshold Configuration x
Collection configuration x

Both the admin role and the user role have permissions to search the following indexes by, default, when no index is specified in the search:

  • vmware-esxilog
  • vmware-inv
  • vmware-perf
  • vmware-taskevent
  • vmware-vclog
Last modified on 22 October, 2021
PREVIOUS
Log in and get started
  NEXT
Dashboards overview

This documentation applies to the following versions of Splunk® App for VMware: 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.7, 4.0.0, 4.0.1, 4.0.3


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters