All Apps and Add-ons

Splunk for VMware Forwarder Appliance can't authenticate to ESXi hosts

colinj
Path Finder

Howdy all,

I'm working on setting up the Splunk for VMware FA and I'm running in to a problem. I've created an appropriate service account in Active Directory and I can connect to vCenter and the ESXi hosts using that service account and the vSphere client. However when I run enginebuilder.py I get the following for all of my ESXi hosts:

[splunkadmin@vsisplunkfa local]$ enginebuilder.py -c -l 2
Checking credentials on esx/i hosts...
   checking permissions of ssv-splunk on ssvcloudn1.dsc.umich.edu...
ERROR: ssv-splunk has insufficient permissions on ssvcloudn1.dsc.umich.edu:
ran command:# logincreator.pl --target ssvcloudn1.dsc.umich.edu --ad 'XXXXX' --adpwd 'XXXXX'
output:
ERROR: cannot authenticate against ssvcloudn1.dsc.umich.edu with ssv-splunk and supplied password

I'm not sure what this means. I've checked and rechecked the role that I created and it has all (and only) of the permissions specified in the Creating service accounts documentation. Do these errors indicate that the Forwarder Appliance can't communicate at all with the ESXi hosts?

Any and all suggestions on how I might proceed are more than welcome.

0 Karma
1 Solution

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

View solution in original post

0 Karma

colinj
Path Finder

And in this case the correct answer is: Check your firewalls.

Seems that we had another firewall between our FA and the ESXi hosts. Once that was take care of everything worked as expected.

0 Karma

gavind
Explorer

Which port id you open here if I may ask? Or was it just an IP exception?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...