icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Gigamon Visibility App For Splunk
SHA256 checksum (gigamon-visibility-app-for-splunk_104.tgz) cc7aa8c3bb49ca8b80c17eab8abcbfb108c4b9d6fca349912d85e07e45959fd1 SHA256 checksum (gigamon-visibility-app-for-splunk_103.tgz) 7afaf77b3461b199ac4576ee5360a6d3767c2fda383cec08b09c9428a4a01358 SHA256 checksum (gigamon-visibility-app-for-splunk_102.tgz) f9f8c25b36cc7aec84acf898802656f8695665ad1c64a40c480566843728b3f2 SHA256 checksum (gigamon-visibility-app-for-splunk_101.tgz) 911a0c0d6328127f4fea0e4a205279b2ab297ad7349a47d35a0061e1cceb77d8
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Gigamon Visibility App For Splunk

Splunk Cloud
This app has been archived. Learn more about app archiving.
Overview
Details
Gigamon Visibility App for Splunk allows a Splunk® Enterprise administrator to collect, store, visualize and analyze the Gigamon Visibility Fabric. Automated searches collect and store aggregated network statistics data from ports and maps within the environment. The FlowMap explorer helps the Splunk Administrator to visualize and trend the traffic policies that are configured within the Visibility Fabric.

Gigamon Visibility App for Splunk is no longer supported by Gigamon. All the functionality in this application (and much more) is available in GigaVUE Fabric Manager (GigaVUE-FM) from Gigamon. Please visit http://www.gigamon.com for more information

Gigamon Visibility App for Splunk is no longer supported by Gigamon. All the functionality in this application (and much more) is available in GigaVUE Fabric Manager (GigaVUE-FM) from Gigamon. Please visit http://www.gigamon.com for more information

Table of Contents

OVERVIEW

  • About Gigamon® Visibility App for Splunk
  • Release notes
  • New Features
  • Support and Resources

INSTALLATION

  • Hardware and Software Requirements
  • Installation Steps
  • Deploy to a Single Server Instance
  • Deploy to a Distributed Deployment
  • Deploy to a Distributed Deployment with Search Head Clustering
  • Deploy to Splunk Cloud

USER GUIDE

  • Data types
  • Lookups
  • Configure Gigamon® Visibility App for Splunk
  • Troubleshooting

Third Party Libraries


OVERVIEW

About Gigamon® Visibility App for Splunk

Author Gigamon, Inc
App Version 1.0.4
Has index-time operations true
Create an index false
Implements summarization true: summary index, Data Model with acceleration

Gigamon® Visibility App for Splunk allows a Splunk® Enterprise administrator to collect, store, and visualize the health and analytics of the Gigamon Visibility Fabric™. By allowing Gigamon® Visibility App for Splunk app access to GigaVUE®-FM, the administrator can have full visibility and reporting across the entire Visibility Fabric. Automated searches collect and store aggregated network statistics from ports and maps within the Visibility Fabric. The Map Explorer enables the administrator to visualize the traffic policies within the Visibility Fabric.

Scripts

Gigamon® Visibility App for Splunk comes with a modular input and the associated classes required to connect and consume the data from the GigaVUE-FM APIs. These files are located within the bin folder of the App.

Release notes

About this release

Version 1.0.4 of Gigamon® Visibility App for Splunk is compatible with:

Splunk Enterprise 6.2 6.3 6.4 6.5 6.6
CIM 4.2
Platforms Platform Independent
Vendor Products GigaVUE-FM 3.1 and above
Lookup file changes This App utilizes KVStore for many lookups, including: GigaVUE-FM instances, Clusters, Flow Maps, cards, and ports.
New features

Gigamon® Visibility App for Splunk includes the following new features:

  • Connect and Consume data from GigaVUE-FM APIs
  • Map Explorer - Visually represents the Visibility Fabric Traffic Policies
  • Visualize Map and port statistics over time
Support and resources

Questions and answers

Access questions and answers specific to Gigamon® Visibility App for Splunk at answers.splunk.com

Support

Support for Gigamon® Visibility App for Splunk is available Monday thru Friday, 8 AM - 5 PM PST by emailing apps@gigamon.com.

INSTALLATION AND CONFIGURATION

Hardware and software requirements

Hardware requirements

  • One or more GigaVUE H Series nodes

Software requirements

To function properly, Gigamon® Visibility App for Splunk requires the following software:

  • Splunk Enterprise 64 bit, v6.2 or above
  • Note: KV store requires 64 bit Splunk installation
  • GigaVUE-FM 3.1 or above

Splunk Enterprise system requirements

Because this App runs on Splunk Enterprise, all of the Splunk Enterprise system requirements apply.

Download

Download Gigamon® Visibility App for Splunk at https://splunkbase.splunk.com .

Installation steps

To install and configure this app on your supported platform, follow these steps:

  1. Download the SPL package from Splunkbase.
  2. Install the App onto the Search head tier, according to Splunk Documentation.
  3. Install the included TA-GigamonForSplunk on the Indexer tiers in your environment, according to Splunk Documentation.
  4. Configure the App to communicate with GigaVUE-FM. You will find the configuration page at "Administration" -> "Configuration" -> "GigaVUE-FM".
Deploying to a Single Server Instance

Follow these steps to install the app in a single server instance of Splunk Enterprise:

  1. Install the App according to the documentation for the version you are using.
  2. Configure the App to communicate with the GigaVUE-FM using the GigaVUE-FM view.
Deploying to a Distributed Deployment

Install to search head

  1. Install the App in one of three supported methods
  2. Configure the App to communicate with the GigaVUE-FM.

Install to indexers

  1. Install the TA-GigamonForSplunk Add-On (included in the appserver/addons folder) onto the Indexer using your technology of choice (Deployment Server / Master Node)

Install to universal forwarders

  1. This App does not support installation to a Universal Forwarder.
Deploying to a Search Head Cluster (SHC)

Install to SHC
1. Install the App using the SHC Deployer
2. Install the TA-GigamonForSplunk Add-On (included in the appserver/addons folder) to the Indexer Tier, according to your configuration.
3. Install the IA-GigamonForSplunk Add-On (included in the appserver/addons/folder) to a Heavy Forwarder. Configure the connection to your GigaVUE-FM from the Heavy Forwarder interface.

Deploying to Splunk Cloud
  1. Engage Splunk Support to have this App installed.

USER GUIDE

Data types

This app provides the index-time and search-time knowledge for the following types of data from Gigamon Visibility Fabric nodes:

Port Information
- sourcetype = gigamon:api:service:port

Audit Event Information
- sourcetype = gigamon:api:service:audit

Licensing Information
- sourcetype = gigamon:api:service:license

Map Information
- sourcetype = gigamon:api:service:maps

Node Information
- sourcetype = gigamon:api:service:node

Stats Information
- sourcetype = gigamon:api:service:stats

User Information
- sourcetype = gigamon:api:service:users

Traffic Analyzer Data
- sourcetype = gigamon:api:service:traffic

Lookups

Gigamon® Visibility App for Splunk contains several KV Stores.

The KV Stores are descriptive in what they contain: giga_clusters, giga_fms, giga_ports, giga_cards, giga_maps.

Configure Gigamon® Visibility App for Splunk

The only configuration out of the box is to connect the App with your GigaVUE-FM. You can do this by accessing the Credential Configuration page. It is located on the Menu under Administration -> Configuration Menu Item as GigaVUE-FM.

To change the location of the data from the main index, update the event type giga_idx with the appropriate index name. You must also change the Modular Input configuration to point to the new index.

For syslog and system event dashboards to get populated, individual Gigavue nodes need to be configured to send syslog to the Splunk instance where GigamonApp is installed. Also a data input need to be created on Splunk for syslog to ingest data from Gigamon nodes.

Troubleshooting

If you find yourself in a situation where the Gigamon® Visibility App for Splunk doesn't work properly, or display the information you thought would be there, here are some simple troubleshooting steps to follow.

1.Start with the Gigamon Visibility App Health dashboard. It is found under the Administration section of the navigation.
1.Check the error sourcetype: sourcetype=GigamonForSplunk:error
1.Check the internal logs: index=_internal source=gigamon
1.Rebuild the lookups: Navigate to the Generate Lookups view under Administration -> Configuration navigation item.
For syslog, individual Gigavue nodes need to be configured to send syslog to the Splunk instance where an input needs to be created

Release Notes

Version 1.0.4
May 12, 2017
Version 1.0.3
May 12, 2017
Version 1.0.2
Oct. 6, 2016
Version 1.0.1
Sept. 21, 2015

Fixed The pre-built panel for proper display.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.