All Apps and Add-ons

Splunk for VMware Forwarder Appliance can't authenticate to ESXi hosts

colinj
Path Finder

Howdy all,

I'm working on setting up the Splunk for VMware FA and I'm running in to a problem. I've created an appropriate service account in Active Directory and I can connect to vCenter and the ESXi hosts using that service account and the vSphere client. However when I run enginebuilder.py I get the following for all of my ESXi hosts:

[splunkadmin@vsisplunkfa local]$ enginebuilder.py -c -l 2
Checking credentials on esx/i hosts...
   checking permissions of ssv-splunk on ssvcloudn1.dsc.umich.edu...
ERROR: ssv-splunk has insufficient permissions on ssvcloudn1.dsc.umich.edu:
ran command:# logincreator.pl --target ssvcloudn1.dsc.umich.edu --ad 'XXXXX' --adpwd 'XXXXX'
output:
ERROR: cannot authenticate against ssvcloudn1.dsc.umich.edu with ssv-splunk and supplied password

I'm not sure what this means. I've checked and rechecked the role that I created and it has all (and only) of the permissions specified in the Creating service accounts documentation. Do these errors indicate that the Forwarder Appliance can't communicate at all with the ESXi hosts?

Any and all suggestions on how I might proceed are more than welcome.

0 Karma
1 Solution

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

View solution in original post

0 Karma

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

0 Karma

gavind
Explorer

Which port id you open here if I may ask? Or was it just an IP exception?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...