erik: api

Search engine for virtual sprawl - vmware app for splunk

**** UPDATE - 08/27/08 ****
I have updated the app with a few fixes found in the field.

  • hopefully fixed issue on AIX (IBM jvm )
  • added output of host/vm name on update messages. It was hard to tell where the messages were coming from
  • added more debugging infor on startup to help debug connection issues.

Things that are still under-investigation.

  • Pointing at lots of ESX servers and not VC. Seems as though some data is not coming back from ESX.
  • Making work with older jvm’s ( currently it seems i require 1.5)

**** Original Post 08/10/08 ****
I’ve wanted to release this a few months ago but the project keeps getting stuck on the back-burner. Finally I’ve cleaned it up and had a few people try it and it seems to work well. I’m sure there are configurations and versions out there that will have issues - please write me back ( my first name at splunk.com ) if it does not work as advertised.

Splunk for Virtualization

I’m looking for some help.
I’ve built a VMWare app for splunk and in the process of doing the same for Xen. These Apps use the VMWare and Xensource API’s to index everything about the VM environment. When combined with splunk instances running within the guest OS you get a very comprehensive historical picture. I’m curious are there any splunk customers out there using VMWare or Xen? I’m looking for usecases so that i better understand how to configure the apps. I’d be curious to know what types of information would be useful to capture and what types of searches would one want to perform. Both Xen and VMWare have so much data available that configuration could be complicated. I’m trying to narrow it down to several useful out of the box configurations. If your have any thoughts comment here or email me at erik at splunk dot com.

Thanks
e.