Splunk® Supported Add-ons

Splunk Add-on for vCenter Logs

Installation and configuration overview for the Splunk Add-on for vCenter Logs

The Splunk Add-on for vCenter logs package contains necessary Index-time and search-time extractions to parse the vCenter logs collected using the syslog/forwarder installed on vCenter server. This overview outlines a full installation of the Splunk Add-on for vCenter Logs on a distributed deployment.

Install the Splunk Add-on for vCenter Logs

Review the deployment diagram and corresponding table for your environment type for details on the install locations for each vCenter logs data collection package. If you are using an on-premises environment, you can forward the data directly to the indexer or using an intermediate forwarder (such as DCN). If you are using the add-on in a cloud environment, you have to forward the data to an intermediate heavy forwarder before you forward the data to cloud indexers.

Install Splunk Add-on for vCenter Logs in an on-premises environment

This deployment diagram reflects the best practice for deploying the Splunk Add-on for vCenter Logs in an on-premises environment.

"Image of best practice deployment diagram for on-premises environments."

This deployment diagram and corresponding table outline the full installation of Splunk Add-on for vCenter Logs in an on-premises environment.

This deployment diagram and the corresponding table represent an alternative option for deploying the Splunk Add-on for vCenter Logs in an on-premises environment.

"Image of deployment diagram for on-premises environments."

Add-on Package Search head Indexer Data collection node (DCN) Dedicated vCenter log forwarder The operation performed by the pacakage
Splunk Add-on for vCenter Logs Splunk_TA_vcenter X X* X X Handles log data collection and parsing of vCenter logs.
Splunk Add-on for VMware Metrics Indexes or Splunk Add-on for VMware Indexes SA-VMWIndex-inframon or SA-VMWIndex X Creates indexes that store vCenter log data.
* If you send syslog data directly to the indexer.

† If you send syslog data directly to the Data Collection Node (DCN).

Install Splunk Add-on for vCenter Logs in a on-cloud environment

This deployment diagram and corresponding table outline the full installation of Splunk Add-on for vCenter Logs in a cloud environment.

"Image of deployment diagram for cloud environments."

Add-on Package Search head Indexer Data collection node (DCN) or intermediate forwarder Dedicated vCenter forwarder The operation performed by the pacakage
Splunk Add-on for vCenter Logs Splunk_TA_vcenter X X X Handles log data collection and parsing of vCenter logs.
Splunk Add-on for VMware Metrics Indexes or Splunk Add-on for VMware Indexes SA-VMWIndex-inframon or SA-VMWIndex X Creates indexes that store vCenter log data.
Last modified on 19 January, 2024
Data collection planning and requirements for the Splunk Add-on for vCenter Logs   Set up your system for the Splunk Add-on for vCenter Logs

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters