All Apps and Add-ons

monitor VMware systems in splunk

kannu
Communicator

Hello All ,

I have vmware environment setup and i make 10 vm's using vsphere client

So I need help in monitoring applications installed on those vm's , like any db application installed on VM ,
Note : i cant install splunk UF on VM , but can install UF on vsphere , SO is there any way in which from Vsphere itself i can monitoring applications installed on VM .

What to monitor : application running or not .

Thanks in advance

Manish Kumar

Tags (1)
0 Karma
1 Solution

koshyk
Super Champion

You got two options
1. The full blow VMware app installation. This is quite complex
2. The easier path of getting ESXi host data . You need to get data by enabling syslog in ESXi and collect to your Forwarder syslog. Then install the addon to parse the data to get valuable information.

View solution in original post

0 Karma

koshyk
Super Champion

You got two options
1. The full blow VMware app installation. This is quite complex
2. The easier path of getting ESXi host data . You need to get data by enabling syslog in ESXi and collect to your Forwarder syslog. Then install the addon to parse the data to get valuable information.

0 Karma

kannu
Communicator

@koshyk

collect to your Forwarder syslog ::::::::: is that heavy forwarder where i receive and route to indexer server

0 Karma

koshyk
Super Champion

Well, most of the people put the syslog directly to Heavy Forwarder Server. So if you don't have separate syslog server, then you can re-use the "syslog" software on the HF server itself as long as it is not heavily loaded.

esxi system (push via syslog) => Syslog server (collect using rsyslog or syslog-ng) => Splunk UF or HF can then send this to Indexer => Install addon on indexer/SH to extract fields (and on HF)

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...