All Apps and Add-ons

What is best approach for ingesting dat from our VMware add-on installation?

mike_k
Path Finder

I am currently running an on-Prem Splunk installation and am trying to figure out the best approach for ingesting data from our VMware environment.

Currently i've got just a very basic setup with syslogs from my ESXi hosts and vCenter going to a Syslog server and monitored by a universal forwarder on the syslog server for forwarding to my indexers. That all works reasonably well, however would like to be able to use some pre-developed dashboards. I have noted that there are a number of VMware add-ons that can be used. Also we are looking to move towards ITSI in the near future so would like to amend the way i ingest WMware data so that it is compatible with this.

At a fundamental level, I think i'm struggling with understanding the difference between "Splunk add-on for VMware" and "Splunk add-on for VMware metrics". Is there a reason why i would pick one of these over the other (or do you normally install both)?

Labels (1)
Tags (2)
0 Karma
1 Solution

Stefanie
Builder

The Splunk Add-on for VMware is used when you want to collect data from your VMware environment but don't have ITSI or IT Essentials Work installed.

If you have IT Essentials Work or ITSI and want that data to be utilized in the ITSI environment then yes, you would install the metrics version. It is the version that the ITSI documentation requires. https://docs.splunk.com/Documentation/ITSI/4.12.0/Entity/aboutVMW

I personally wouldn't see the point in installing both. They both require the use of DCNs to collect information from the API.

 

If you are interested in ITSI, IT Essentials Work is a watered-down version and with it you can check out some of the included VMWare dashboards that work with the logs you are ingesting. 

View solution in original post

mike_k
Path Finder

Thanks for that reply Stefanie. So the options then are:

1) install "Splunk add-on for VMware" and utilise this with the "Splunk app for VMware"

2) install "Splunk add-on for VMware Metrics" and utilise this with either the "IT Essentials Work" or "IT Service Intelligence" apps.

From what i can see Option 1 (or at least the "Splunk App for VMware"), is being EOL'ed this year, and Option 2 appears to be the way supported by Splunk going forwards.

Stefanie
Builder

That's correct. 🙂

0 Karma

Stefanie
Builder

The Splunk Add-on for VMware is used when you want to collect data from your VMware environment but don't have ITSI or IT Essentials Work installed.

If you have IT Essentials Work or ITSI and want that data to be utilized in the ITSI environment then yes, you would install the metrics version. It is the version that the ITSI documentation requires. https://docs.splunk.com/Documentation/ITSI/4.12.0/Entity/aboutVMW

I personally wouldn't see the point in installing both. They both require the use of DCNs to collect information from the API.

 

If you are interested in ITSI, IT Essentials Work is a watered-down version and with it you can check out some of the included VMWare dashboards that work with the logs you are ingesting. 

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...