![]() Download Splunk Add-on for vCenter Logs from Splunkbase and extract its components.The default password for the Splunk Enterprise admin user is changeme. Configure the forwarder in the nf file for each forwarder installed on a vCenter server system. Configure the forwarder on your vCenter server systems to send data to your indexers.For instructions, go to Install a Universal Forwarder on Windows. Use a Splunk universal forwarder to forward the log data from your Windows vCenter server to the indexer. Use the Splunk Add-on for vCenter Logs to collect vCenter server log data. VCenter Log Collection (Windows vCenter and vCSA) Collect Windows VMware vCenter Server log data Go to the VMware Knowledge Base for detailed installation instructions. If you use vSphere 5.0 or 5.0 update 1, be sure to add two missing WSDL files that the app needs to make API calls to vCenter.Go to the known issues in the release notes the Splunk Add-on for VMware Metrics for details on applying the patch. If you use vCenter Server 5.0 and 5.0.1, apply a patch to manage a known issue with the servers.Validate and patch vCenter server systems, add WSDL files If there is no web.conf file, create the file. Open the web.conf file with a text editor.On your DCN, navigate to $SPLUNK_HOME\etc\system\local.You might need to set your DCNs to honor TLS protocols when making requests to the vCenter APIs. Select the appropriate permissions for the role.On the Add new Role screen, enter a name for the role, for example, splunkreader.Under Administration select Roles > Add Role.Open the vSphere client and connect to the vCenter server.Contact your AD administrator to learn how to do this for your environment.Ĭreate roles on each vCenter server in your environment The steps to create a service account within Active Directory depends on your environment. However, if you use multiple AD domains, then create a service account in each domain that your VMware environment uses. Most VMware environments use a single Active Directory domain for authentication. Verify that you have a local Windows user compatible with the vSphere permissions system.įor machines that participate in an Active Directory (AD) domain, create a service account in the given domain using the control panel in Windows Server. The new user account displays as a standard user and the account shows that it is password protected. On the Change an Account screen, select Create a password` and assign the user a password.On the Manage Accounts screen, select the new user.Enter a name for the account, for example, splunksvc.In the Manage Accounts window, select Create a new account.On the User Accounts screen, select Add or remove user accounts. ![]() Log in to the Windows OS with an administrator account.If you add a new vCenter server user as administrator, the user automatically assumes an Administrator role in vSphere.Ĭreate a local user on your Windows OS (vCenter) machine If you use ActiveDirectory for authentication on your Windows OS (vCenter) machines, go to Create users in ActiveDirectory in this topic. You have to have a user account to authenticate with vCenter. If you encounter issues setting the correct permissions for vCenter server accounts, go to the User account permissions in the Splunk Add-on for VMware Metrics manual. You can use an existing vCenter server account credentials, or create a new account for the Splunk App for VMware to access the vCenter server data. These credentials are required for DCN configuration. The Splunk App for VMware uses the credentials when the data connection node (DCN) polls vCenter server systems for performance, hierarchy, inventory, task, and event data. These credentials allow the Splunk Add-on for VMware Metrics and the Splunk Add-on for VMware read-only API access to the appropriate metrics on each vCenter server system in the environment. Obtain VMware vCenter server account credentials for each vCenter server system. Prepare to collect data Set up a vCenter Server user account Windows-based vCenter environments require a Splunk platform forwarder and the splunk_TA_vcenter package. You don't need to install anything on the vCSA servers to collect this data. VCenter logs contain information about access to the vCenter environment, audit information (who assigned permissions, added/edited/removed VMs), and health information about vCenter's processes.įor vCSA servers, vCSA's native syslog forwarding is used to pass this information to your Splunk platform. Configure the Splunk Add-on for vCenter logs to collect vCenter log data
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |