Configure Splunk App for VMware to collect data from vCenter Server
Configure a Data Collection Node
The Collection Configuration dashboard, on the search head, manages the Data Collection Nodes (DCNs). Register all data collection nodes with the Collection Configuration dashboard in order to collect data from vCenter Server. You must configure each DCN separately with the scheduler.
Register a DCN with the scheduler
- Log in to Splunk Web on the search head as admin.
- From the App menu, select VMware.
- From the Settings menu select Collection Configuration, and click +.
- Enter the settings for the data collection node, and click Save.
See the Data Collection Node configuration settings table.
Field Value Splunk Forwarder URI The address or port of the DCN. For example, https://<host_name_or_ip_address_of_DCN>:8089. Splunk Forwarder Username admin. Splunk Forwarder Password The administrator password. Make sure this password is not the Splunk Enterprise default admin password (changeme). Worker Processes Define the number of worker processes you want on the node. This is the number of processes you can run on the data collection node to process the data and forward it to the indexer(s). You can run a maximum of 30 processes per node at the default configuration. The number of worker processes must be one fewer than the number of CPU cores the vCenter Server system granted to the DCN. For example, if the DCN has four CPU cores, the number of worker processes is three.
- Confirm that you correctly configured the DCN by verifying that the DCN, credential validation, and add-on validation all display a green check.
- Repeat the steps for each DCN.
Configure vCenter Server
Add a vCenter Server system as a source of data in your environment.
- On the Collection Configuration dashboard, in the Virtual Centers panel, click +.
- Enter the settings for the vCenter Server.
Field Value Virtual Center FQDN The fully-qualified domain name for the vCenter server. For example,
VC Username The user name that you configured in vCenter Server for Splunk Enterprise. Use the format
username@domainif the user is an Active Directory account.
VC Password The password that you configured in vCenter Server for Splunk Enterprise.
- For the initial installation, pull 20 or fewer hosts. If the vCenter Server manages other servers, make sure that Collect form all hosts and whitelist-specific hosts are not selected.
- Click Save.
- Verify that each of the vCenter Server entries displays a green check.
- Click Start Scheduler. The Distributed Collection Scheduler is running when the button label is Stop Scheduler.
- Approximately ten minutes after you start the scheduler, access the search head and navigate to the Splunk Search field.
- Type a search string to test data collection.
- Confirm that the search returns results. Dashboards and some of the other graphics might take up to 60 minutes to populate.
Test DCN and vCenter Server configurations
Configure the data collection node and system settings
Collect VMware vCenter Server Linux Appliance log data
This documentation applies to the following versions of Splunk® App for VMware (Legacy): 4.0.4