All Apps and Add-ons

Splunk for VMware Forwarder Appliance can't authenticate to ESXi hosts

colinj
Path Finder

Howdy all,

I'm working on setting up the Splunk for VMware FA and I'm running in to a problem. I've created an appropriate service account in Active Directory and I can connect to vCenter and the ESXi hosts using that service account and the vSphere client. However when I run enginebuilder.py I get the following for all of my ESXi hosts:

[splunkadmin@vsisplunkfa local]$ enginebuilder.py -c -l 2
Checking credentials on esx/i hosts...
   checking permissions of ssv-splunk on ssvcloudn1.dsc.umich.edu...
ERROR: ssv-splunk has insufficient permissions on ssvcloudn1.dsc.umich.edu:
ran command:# logincreator.pl --target ssvcloudn1.dsc.umich.edu --ad 'XXXXX' --adpwd 'XXXXX'
output:
ERROR: cannot authenticate against ssvcloudn1.dsc.umich.edu with ssv-splunk and supplied password

I'm not sure what this means. I've checked and rechecked the role that I created and it has all (and only) of the permissions specified in the Creating service accounts documentation. Do these errors indicate that the Forwarder Appliance can't communicate at all with the ESXi hosts?

Any and all suggestions on how I might proceed are more than welcome.

0 Karma
1 Solution

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

View solution in original post

0 Karma

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

0 Karma

gavind
Explorer

Which port id you open here if I may ask? Or was it just an IP exception?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...