All Apps and Add-ons

monitor VMware systems in splunk

kannu
Communicator

Hello All ,

I have vmware environment setup and i make 10 vm's using vsphere client

So I need help in monitoring applications installed on those vm's , like any db application installed on VM ,
Note : i cant install splunk UF on VM , but can install UF on vsphere , SO is there any way in which from Vsphere itself i can monitoring applications installed on VM .

What to monitor : application running or not .

Thanks in advance

Manish Kumar

Tags (1)
0 Karma
1 Solution

koshyk
Super Champion

You got two options
1. The full blow VMware app installation. This is quite complex
2. The easier path of getting ESXi host data . You need to get data by enabling syslog in ESXi and collect to your Forwarder syslog. Then install the addon to parse the data to get valuable information.

View solution in original post

0 Karma

koshyk
Super Champion

You got two options
1. The full blow VMware app installation. This is quite complex
2. The easier path of getting ESXi host data . You need to get data by enabling syslog in ESXi and collect to your Forwarder syslog. Then install the addon to parse the data to get valuable information.

0 Karma

kannu
Communicator

@koshyk

collect to your Forwarder syslog ::::::::: is that heavy forwarder where i receive and route to indexer server

0 Karma

koshyk
Super Champion

Well, most of the people put the syslog directly to Heavy Forwarder Server. So if you don't have separate syslog server, then you can re-use the "syslog" software on the HF server itself as long as it is not heavily loaded.

esxi system (push via syslog) => Syslog server (collect using rsyslog or syslog-ng) => Splunk UF or HF can then send this to Indexer => Install addon on indexer/SH to extract fields (and on HF)

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...