Migrate from the Splunk Supporting Add-on for VMware or the Splunk App for VMware to the Content Pack for VMware Dashboards and Reports
The Content Pack for VMware Dashboards and Reports replicates the dashboards and reports available in the Splunk Supporting Add-on for VMware and the Splunk App for VMware. Migrate from these legacy apps to the content pack to take advantage of a consolidated experience within one app, either ITSI or IT Essentials Work. In addition, you can upgrade all content packs by upgrading the one app, the Splunk App for Content Packs.
If you are currently using Splunk Supporting Add-on for VMware your deployment might look like the following image and table:
Component | Search head | Scheduler | Indexer | Data Collection Node (DCN) | ESXi log forwarder | vCenter log forwarder |
---|---|---|---|---|---|---|
Splunk App for VMware | ✓ | |||||
Splunk Add-on for VMware | ✓ | ✓ | ✓ | |||
Splunk Add-on for ESXi Logs | ✓ | ✓ | ✓ | |||
Splunk Add-on for vCenter Logs | ✓ | ✓ | ✓ | |||
Splunk Add-on for VMware Indexes | ✓ | |||||
Splunk Add-on for VMware Extractions | ✓ |
You can review the dashboards included in the Content Pack for VMware Dashboards before you migrate. See Dashboard reference for the Content Pack for VMware Dashboards and Reports.
Migration steps for Cloud environments
Splunk App for VMware consumes data produced from Splunk Add-on for VMware. The Content Pack for VMware Dashboards and Reports consumes data produced from Splunk Add-on for VMware Metrics.
Before you submit a request for migration
Before you submit a request to migrate from Splunk App for VMware to Content Pack for VMware Dashboards and Reports, make sure that you have configured Splunk Add-on for VMware Metrics to forward data in your Splunk Cloud environment. See Installation and Configuration Overview of Splunk Add-on for VMware Metrics to install and configure Splunk Add-on for VMware Metrics in your environment.
After Splunk Add-on for VMware Metrics is configured to ingest the data in Splunk Cloud environment, to start migrating from Splunk App for VMware to Content Pack for VMware Dashboards and Reports on Cloud, open a service ticket on the Splunk Support Portal, in the Support and Services section. Splunk Cloud TechOps will assist you with migration from Splunk App for VMware to Content Pack for VMware Dashboards and Reports.
Migration steps for On-Premises environments
Splunk App for VMware consumes the data collected by Splunk Add-on for VMware, while Content Pack for VMware Dashboards and Reports consumes the data collected by Splunk Add-on for VMware Metrics.
Update the VMware data collection mechanism
If you plan to use Content Pack for VMware Dashboards and Reports Content Pack in your environment, then configure Splunk Add-on for VMware Metrics to collect the VMware data in that environment. For steps to install and configure Splunk Add-on for VMware Metrics, see Installation and Configuration Overview of Splunk Add-on for VMware Metrics.
Before you migrate
Before migrating to Content Pack for VMware Dashboards and Reports, make sure to follow the steps below to make a backup of your custom configurations and lookups.
- Make a backup of the following directories present in the splunk_for_vmware package present in
$SPLUNK_HOME/etc/apps
on the search head where the App is being used:/local
directory that contains all the local configurations under conf files/lookups
directory that contains the CSV lookups
- Make a backup of the configuration files from the local folder of the SA-VMW-HierarchyInventory package on the search head where App is being used:
datamodels.conf
- Make a backup of the lookups from the SA-VMW-HierarchyInventor/lookups package in
$SPLUNK_HOME/etc/apps
on the search head where the App is being used:DatastoreList.csv
FullHierarchy.csv
TimeAboutHost.csv
TimeClusterServicesAvailability.csv
TimeDatastoreSummary.csv
TimeInvHostHardwareAndLicense.csv
UniqueNameLookup.csv
- Make a backup of the lookups from the SA-VMW-Performance package on the search head where the App is being used:
ACFields.csv
HSFieldList.csv
HSInstanceList.csv
- Make a backup of the lookups from the SA-VMW-LogEventTask package on the search head where the App is being used:
vmware_event_lookup.csv
vmware_task_lookup.csv
- Perform the following steps on each role present in the instance:
- Navigate to Settings > Roles
- Click on Edit > Edit
- Deselect the
splunk_vmware_admin
role from the Inheritance tab if shows as selected. - Click on Save.
- Perform the following steps on user inheriting the
splunk_vmware_user
role:- Navigate to Settings > Users.
- Click on Edit > Edit.
- Navigate to Assign Roles.
- From Selected item(s) > Remove
splunk_vmware_user
role. - Click on Save.
Steps to migrate from Splunk App for VMware to Content Pack for VMware Dashboards and Reports
Follow the procedure below to migrate from Splunk App for VMware to Content Pack for VMware Dashboards and Reports. Make sure you've backed up existing lookups and custom configurations before you start following the steps below.
- Perform the steps below on each Search Head present in your deployment to disable the Splunk App for VMware: [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/splunk_for_vmware/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for VMware Performance: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-VMW-Performance/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for Threshold: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-Threshold/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for VMware Log Event Task: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-VMW-LogEventTask/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for VMware NetApp Utils: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-VMNetAppUtils/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for VMware Hierarchy Inventory: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-VMW-HierarchyInventory/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk Add-on for VMware Extractions: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/TA-VMW-FieldExtractions/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk Add-on for VMware: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/Splunk_TA_vmware/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Perform the steps below on each Search Head present in your deployment to disable the Splunk App for Hydra: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) Navigate to [/topic/topic/body/section/ol/ol/li/codeph {""}) {SPLUNK_HOME}/etc/apps/SA-Hydra/local/app.conf (codeph] (create app.conf file in local directory if it is not present) (li] [/topic/topic/body/section/ol/ol/li {""}) Edit the "state" property of the "install" stanza as shown below: (li] (ol] [/topic/topic/body/section/ol/codeblock {""}) [install] state = disabled (codeblock] [/topic/topic/body/section/ol/li {""}) Restart the all the Search Heads and Indexers present in your deployment. (li] [/topic/topic/body/section/ol/codeblock {""}) $SPLUNK_HOME/bin/splunk restart (codeblock] [/topic/topic/body/section/ol/li {""}) Install IT Service Intelligence or IT Essentials Work on the same search head with VMware data according to your type of deployment. Refer to these topics in the Splunk IT Service Intelligence Install and Upgrade Manual: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ITSI_4.20.0_Install_Install) (xref]. (li] [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ITSI_4.20.0_Install_InstallDD) (xref]. (li] [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ITEWork_4.20.0_Install_Install) (xref]. (li] (ol] [/topic/topic/body/section/ol/li {""}) Install the Splunk App for Content Packs according to your type of deployment: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ContentPackApp_2.3.0_Overview_Install__Install_the_Splunk_App_for_Content_Packs_on_a_single.2C_on-premises_environment) (xref]. (li] [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ContentPackApp_2.3.0_Overview_Install__Install_the_Splunk_App_for_Content_Packs_on_a_distributed_environment) (xref]. (li] (ol] [/topic/topic/body/section/ol/li {""}) Install the Splunk Add-on for VMware Metrics according to your type of deployment: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (AddOns_released_VMWmetrics_InstallOverview__Deploy_the_Splunk_Add-on_for_VMware_Metrics_on-prem) (xref] (li] [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (ContentPackApp_2.3.0_Overview_Install__Install_the_Splunk_App_for_Content_Packs_on_a_distributed_environment) (xref] (li] (ol] [/topic/topic/body/section/ol/li {""}) Install the Splunk Add-on for VMware Metrics Indexes according to your type of deployment: (li] [/topic/topic/body/section/ol/ol {""}) [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (AddOns_released_VMWmetricsindexes_Install__Install_and_configure_in_an_on-premises_environment) (xref] (li] [/topic/topic/body/section/ol/ol/li {""}) [/topic/topic/body/section/ol/ol/li/xref {"unresolved-reference"}) ERROR - unresolved reference (AddOns_released_VMWmetricsindexes_Install__Install_and_configure_in_a_cloud_environment) (xref] (li] (ol]