Splunk® Supported Add-ons

Splunk Add-on for vCenter Logs

Install the Splunk Add-on for vCenter Logs

The Splunk Add-on for vCenter logs receives the vCenter logs data via syslog/universal forwarder installed on the vCenter server and the data is ingested in the vmware-vclog index. The definition for the required index is present in the Splunk Add-on for VMware Metrics Indexes package or the Splunk Add-on for VMware Indexes package. If you are using Splunk Add-On for VMware Metrics you have to install the indexes package by following the Install and Configure Splunk Add-on for VMware Metrics Indexes steps. If you are using Splunk Add-On for VMware you have to install the indexes package by following the Install and Configure Splunk Add-on for VMware Indexes steps.

Install the Splunk Add-on for vCenter Logs to the environment tier to collect data.

Install Splunk Add-on for vCenter Logs to a cloud environment

  1. Log in to your search head.
  2. On the Splunk Web home page, select the gear icon next to Apps.
  3. Select Browse More Apps.
  4. Search for the "Splunk Add-on for vCenteri logs" and select Install.
  5. Enter your Splunk.com login credentials.
  6. Read and accept the terms and conditions, and select Login and Download.
  7. Go to Apps > Manage Apps to review the installed app on the Apps page.

The vmware-vclog index, which is part of the SA-VMWIndex-inframon, package is required. If you are using Splunk Add-On for VMware Metrics you have to install the Splunk Add-on for VMware Metrics Indexes package. If you are using Splunk Add-On for VMware you have to Install the Add-on for VMware Indexes package.

Last modified on 21 July, 2021
Set up your system for the Splunk Add-on for vCenter Logs   Configure the Splunk Add-on for vCenter logs to collect vCenter log data

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters