All Apps and Add-ons

How do I configure the VMware NSX-T Splunk App?

mbavlsik
Engager

I have installed the NSX-T Splunk app on my search head, and I have configured syslog data to come to splunk. I can query the syslog data independently, but I'm not sure how to configure the app to reference the data. I don't see any "configure" button and I can't find any documentation. Can someone point me towards useful documentation for configuring the app?

0 Karma

tuanloc2503
New Member

Please reach out to your Sale rep of VMware and we will fix it for you. Looks like you missed configuration in Splunk plugin for NSX-T 2.4 or 2.5

0 Karma

ttokkaris
New Member

This app is not populating any data at all in the dashboards.
Is there a guide that I can follow?
I can see data coming in in the search

0 Karma

tuanloc2503
New Member

check with Sale rep and they will escalade for you- miss configuration in your setup

0 Karma

smastersartc
Engager

When querying the data outside of the NSX-T app do you need to specify an index in your search? If you are normally doing this anyway, try and search without the index and see if you are still receiving results.

If not, you'll need to add the index as a default index for the user group that will be using the NSX-T Splunk app.

Default indexes can be set under: Settings > Access Controls > Roles, and clicking on the role you wish to edit. The specifics of these menus will change a little between versions.

0 Karma

jme147
Engager

Any update on this thread would be helpful. I am trying to configure the app on an 8.x splunk instance pointing to an NSX-T 3.x instance. Is there a configuration needed to point the app at the NSX manager?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...