I have installed the NSX-T Splunk app on my search head, and I have configured syslog data to come to splunk. I can query the syslog data independently, but I'm not sure how to configure the app to reference the data. I don't see any "configure" button and I can't find any documentation. Can someone point me towards useful documentation for configuring the app?
Please reach out to your Sale rep of VMware and we will fix it for you. Looks like you missed configuration in Splunk plugin for NSX-T 2.4 or 2.5
This app is not populating any data at all in the dashboards.
Is there a guide that I can follow?
I can see data coming in in the search
check with Sale rep and they will escalade for you- miss configuration in your setup
When querying the data outside of the NSX-T app do you need to specify an index in your search? If you are normally doing this anyway, try and search without the index and see if you are still receiving results.
If not, you'll need to add the index as a default index for the user group that will be using the NSX-T Splunk app.
Default indexes can be set under: Settings > Access Controls > Roles, and clicking on the role you wish to edit. The specifics of these menus will change a little between versions.
Any update on this thread would be helpful. I am trying to configure the app on an 8.x splunk instance pointing to an NSX-T 3.x instance. Is there a configuration needed to point the app at the NSX manager?