Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Gigamon Visibility App For Splunk
MD5 checksum (gigamon-visibility-app-for-splunk_102.tgz) 145e1d9bbea9bd2d37976d121bdd6fd8 MD5 checksum (gigamon-visibility-app-for-splunk_101.tgz) cdcacca1fca57c63a74b62765087e8d1
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Gigamon Visibility App For Splunk

Overview
Details
Gigamon Visibility App for Splunk allows a Splunk® Enterprise administrator to collect, store, visualize, and analyze the Gigamon Visibility Fabric. Automated searches collect and store aggregated network statistics data from ports and maps within the environment. The FlowMap explorer helps the Splunk Administrator to visualize and trend the traffic policies that are configured within the Visibility Fabric.

Table of Contents

OVERVIEW

  • About Gigamon® Visibility App for Splunk
  • Release notes
  • New Features
  • Support and Resources

INSTALLATION

  • Hardware and Software Requirements
  • Installation Steps
  • Deploy to a Single Server Instance
  • Deploy to a Distributed Deployment
  • Deploy to a Distributed Deployment with Search Head Clustering
  • Deploy to Splunk Cloud

USER GUIDE

  • Data types
  • Lookups
  • Configure Gigamon® Visibility App for Splunk
  • Troubleshooting

Third Party Libraries


OVERVIEW

About Gigamon® Visibility App for Splunk

Author Gigamon, Inc
App Version 1.0.1
Has index-time operations true
Create an index false
Implements summarization true: summary index, Data Model with acceleration

Gigamon® Visibility App for Splunk allows a Splunk® Enterprise administrator to collect, store, and visualize the health and analytics of the Gigamon Visibility Fabric™. By allowing Gigamon® Visibility App for Splunk app access to GigaVUE®-FM, the administrator can have full visibility and reporting across the entire Visibility Fabric. Automated searches collect and store aggregated network statistics from ports and maps within the Visibility Fabric. The Map Explorer enables the administrator to visualize the traffic policies within the Visibility Fabric.

Scripts

Gigamon® Visibility App for Splunk comes with a modular input and the associated classes required to connect and consume the data from the GigaVUE-FM APIs. These files are located within the bin folder of the App.

Release notes

About this release

Version 1.0.1 of Gigamon® Visibility App for Splunk is compatible with:

Splunk Enterprise 6.2
CIM 4.2
Platforms Platform Independent
Vendor Products GigaVUE-FM 3.1 and above
Lookup file changes This App utilizes KVStore for many lookups, including: GigaVUE-FM instances, Clusters, Flow Maps, cards, and ports.
New features

Gigamon® Visibility App for Splunk includes the following new features:

  • Connect and Consume data from GigaVUE-FM APIs
  • Map Explorer - Visually represents the Visibility Fabric Traffic Policies
  • Visualize Map and port statistics over time
Support and resources

Questions and answers

Access questions and answers specific to Gigamon® Visibility App for Splunk at answers.splunk.com

Support

Support for Gigamon® Visibility App for Splunk is available Monday thru Friday, 8 AM - 5 PM PST by emailing App.Splunk@gigamon.com.

INSTALLATION AND CONFIGURATION

Hardware and software requirements

Hardware requirements

  • One or more GigaVUE H Series nodes

Software requirements

To function properly, Gigamon® Visibility App for Splunk requires the following software:

  • Splunk, v6.2 or above
  • GigaVUE-FM 3.1 or above

Splunk Enterprise system requirements

Because this App runs on Splunk Enterprise, all of the Splunk Enterprise system requirements apply.

Download

Download Gigamon® Visibility App for Splunk at https://splunkbase.splunk.com .

Installation steps

To install and configure this app on your supported platform, follow these steps:

  1. Download the SPL package from Splunkbase.
  2. Install the App onto the Search head tier, according to Splunk Documentation.
  3. Install the included TA-GigamonForSplunk on the Indexer tiers in your environment, according to Splunk Documentation.
  4. Configure the App to communicate with GigaVUE-FM. You will find the configuration page at "Administration" -> "Configuration" -> "GigaVUE-FM".
Deploying to a Single Server Instance

Follow these steps to install the app in a single server instance of Splunk Enterprise:

  1. Install the App according to the documentation for the version you are using.
  2. Configure the App to communicate with the GigaVUE-FM using the GigaVUE-FM view.
Deploying to a Distributed Deployment

Install to search head

  1. Install the App in one of three supported methods
  2. Configure the App to communicate with the GigaVUE-FM.

Install to indexers

  1. Install the TA-GigamonForSplunk Add-On (included in the appserver/addons folder) onto the Indexer using your technology of choice (Deployment Server / Master Node)

Install to universal forwarders

  1. This App does not support installation to a Universal Forwarder.
Deploying to a Search Head Cluster (SHC)

Install to SHC
1. Install the App using the SHC Deployer
2. Install the TA-GigamonForSplunk Add-On (included in the appserver/addons folder) to the Indexer Tier, according to your configuration.
3. Install the IA-GigamonForSplunk Add-On (included in the appserver/addons/folder) to a Heavy Forwarder. Configure the connection to your GigaVUE-FM from the Heavy Forwarder interface.

Deploying to Splunk Cloud
  1. Engage Splunk Support to have this App installed.

USER GUIDE

Data types

This app provides the index-time and search-time knowledge for the following types of data from Gigamon Visibility Fabric nodes:

Port Information
- sourcetype = gigamon:api:service:port

Audit Event Information
- sourcetype = gigamon:api:service:audit

Licensing Information
- sourcetype = gigamon:api:service:license

Map Information
- sourcetype = gigamon:api:service:maps

Node Information
- sourcetype = gigamon:api:service:node

Stats Information
- sourcetype = gigamon:api:service:stats

User Information
- sourcetype = gigamon:api:service:users

Traffic Analyzer Data
- sourcetype = gigamon:api:service:traffic

Lookups

Gigamon® Visibility App for Splunk contains several KV Stores.

The KV Stores are descriptive in what they contain: giga_clusters, giga_fms, giga_ports, giga_cards, giga_maps.

Configure Gigamon® Visibility App for Splunk

The only configuration out of the box is to connect the App with your GigaVUE-FM. You can do this by accessing the Credential Configuration page. It is located on the Menu under Administration -> Configuration Menu Item as GigaVUE-FM.

To change the location of the data from the main index, update the event type giga_idx with the appropriate index name. You must also change the Modular Input configuration to point to the new index.

Troubleshooting

If you find yourself in a situation where the Gigamon® Visibility App for Splunk doesn't work properly, or display the information you thought would be there, here are some simple troubleshooting steps to follow.

1.Start with the Gigamon Visibility App Health dashboard. It is found under the Administration section of the navigation.
1.Check the error sourcetype: sourcetype=GigamonForSplunk:error
1.Check the internal logs: index=_internal source=gigamon
1.Rebuild the lookups: Navigate to the Generate Lookups view under Administration -> Configuration navigation item.

Release Notes

Version: 1.0.2

Oct. 6, 2016, 11:15 p.m.

Platform Independent

6.5, 6.4, 6.3, 6.2

Version: 1.0.1

Fixed The pre-built panel for proper display.

Sept. 21, 2015, 10:28 p.m.

Platform Independent

6.2

40
Installs
411
Downloads
Share Subscribe LOGIN TO DOWNLOAD
Version
1.0.2
Category
IT Operations
Security, Fraud & Compliance
Product Support
Splunk Enterprise
Splunk Cloud
Content Type
App
Splunk Versions
6.5
6.4
6.3
6.2
Licensing
Gigamon Supplemental End User License Agreement
Platforms
Platform Independent
Built by
Gigamon Inc.
Contact Developer
Subscribe Share

Splunk Certification Program

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2017 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.