Data collection planning and requirements for the Splunk Add-on for VMware ESXi Logs
Before you deploy the Splunk Add-on for VMware ESXi Logs review these requirements.
Splunk platform version requirements
- For Splunk Enterprise system requirements, go to System requirements for use of Splunk Enterprise on-premises in the Splunk Enterprise Installation Manual.
- If you're managing on-premises forwarders to get data into Splunk Cloud, go to System requirements for use of Splunk Enterprise on-premises, which includes information about forwarders.
Current add-on version | Supported versions of Splunk Enterprise |
---|---|
4.2.1 |
|
VMware index
The ESXi logs data from the forwarder is stored in this index. The Splunk Add-on for ESXi Logs package indexes the data into the vmware-esxihost index. If you are using Splunk Add-on for VMware Metrics, then you need to install Splunk Add-on for VMware Metrics Indexes in your environment to get this index. If you are using Splunk Add-on for VMware, then you need to install Splunk Add-on for VMware Indexes in your environment to get the index.
Index | Description |
---|---|
vmware-esxihost | Stores ESXi host log data. |
Data volume requirements
The expected ESXi logs data volume ingested by this package in a typical environment is 125-235 MB per host per day. The actual volume varies depending on the log data collected and the number of virtual machines on a host.
Data type | Data volumne |
---|---|
ESXi host logs | 135-235 MB per host per day |
Add-on Version compatibility with Splunk Add-on for VMware Metrics and its prerequisite add-ons
Splunk Add-on for VMware Metrics version | Compatible Splunk Add-on for VMware ESXi Logs version | Compatible Splunk Add-on for VMware Metrics Indexes version | Compatible vCenter version | Compatible ESXi version |
---|---|---|---|---|
4.2.1 | 4.2.1 | 4.2.1 |
|
|
4.2.4 | 4.2.1 | 4.2.1 |
|
|
Add-on Version compatibility with Splunk Add-on for VMware and its prerequisite add-ons
vCenter versions 5.x and 6.x are End of Life (EOL).
Splunk Add-on for VMware version | Compatible Splunk Add-on for VMware ESXi Logs version | Compatible Splunk Add-on for VMware Indexes version | Compatible vCenter version | Compatible ESXi version |
---|---|---|---|---|
4.0.3 | 4.2.1 | 4.0.3 |
|
|
4.0.4 | 4.2.1 | 4.0.3 |
|
|
4.0.5 | 4.2.1 | 4.0.3 |
|
|
4.0.6 | 4.2.1 | 4.0.3 |
|
|
PREVIOUS Release history for the Splunk Add-on for VMware ESXi Logs |
NEXT Installation and configuration overview for the Splunk Add-on for VMware ESXi Logs |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!