I'm trying to add VMware vSphere data using the Splunk app for infrastructure. When I try to, all I get is an alert "You have to install the Splunk VMware Add-on for ITSI and its components before you start collecting VMware data." I'm unclear on how to get around this issue since I have installed the necessary components. According to documentation https://docs.splunk.com/Documentation/InfraApp/2.0.4/Install/VMWInstall?ref=hk I need to install ITSI, which I have, and install SA-VMWIndex, Splunk_TA_esxilogs, and Splunk_TA_vcenter, which are all components inside of the vmware_ta_itsi parent directory that is a part of the ITSI install. I made sure the components within vmware_ta_itsi were also in $SPLUNK_HOME/etc/apps/ like the documentation says they should be.
... View more
I'm trying to ingest metric data from a Virtual Machine Linux box, using syslog-ng and Splunk Universal Forwarder. It's for an application, so on my windows box I'm trying to make the configuration files for transforms and props in /etc/apps/app_name/local directory. It's currently working for another box with rsyslog instead of syslog-ng. For some reason it isn't with syslog-ng.
INGEST_EVAL = metric_name=Metric
WRITE_META = true
I'm pretty sure these are the issue as to why it isn't working, but I don't know what I've done wrong.
I hope I explained this properly. If you need more information, let me know. I would greatly appreciate some help on this, I'm stuck.
... View more