{"id":70467,"date":"2026-08-04T09:00:22","date_gmt":"2026-08-04T07:00:22","guid":{"rendered":"https:\/\/nolabnoparty.com\/?p=70467"},"modified":"2026-08-01T15:27:16","modified_gmt":"2026-08-01T13:27:16","slug":"how-to-install-veeam-app-for-splunk","status":"publish","type":"post","link":"https:\/\/nolabnoparty.com\/en\/how-to-install-veeam-app-for-splunk\/","title":{"rendered":"How to install Veeam App for Splunk"},"content":{"rendered":"<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-70468\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/07\/install-veeam-app-for-splunk-01.jpg\" alt=\"\" width=\"602\" height=\"202\" title=\"\"><\/p>\n<p>The Veeam App for Splunk is a free solution provided by <a href=\"https:\/\/nolabnoparty.com\/en\/using-the-veeam-deployment-kit\/\">Veeam<\/a> to <strong>monitor your backup infrastructure<\/strong> by centralizing backup job statuses into a single Dashboard.<\/p>\n<p>Depending on your installed Splunk version, the application can be deployed in either a <strong>Windows or a Linux environment<\/strong>.<!--more--><\/p>\n<p>&nbsp;<\/p>\n<h2>Prerequisites<\/h2>\n<p>Before beginning the installation, ensure the following prerequisites are met:<\/p>\n<ul>\n<li>A working <a href=\"https:\/\/nolabnoparty.com\/en\/veeam-using-the-four-eyes-authorization\/\">Veeam Backup &amp; Replication<\/a> infrastructure.<\/li>\n<li>A Linux or Windows machine to install <a href=\"https:\/\/www.splunk.com\/en_us\/products\/splunk-enterprise.html\" target=\"_blank\" rel=\"noopener\">Splunk Enterprise<\/a> to display data collected by the Veeam application.<\/li>\n<li>The <a href=\"https:\/\/splunkbase.splunk.com\/app\/7312\" target=\"_blank\" rel=\"noopener\">Veeam App for Splunk<\/a> downloaded from Splunkbase.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Install Splunk Enterprise on Ubuntu Linux<\/h2>\n<p>To avoid Windows licensing fees, a Linux OS is often the ideal choice for running Splunk Enterprise. <strong>SSH<\/strong> into your Ubuntu system and follow these steps to install it.<\/p>\n<p>Using the <em>wget<\/em> command, download the <strong>Splunk Debian package<\/strong> in the <em>\/tmp<\/em> folder.<\/p>\n<p><span style=\"color: #0000ff;\"># cd \/tmp<br \/>\n# wget -O splunk-10.4.2-33c3bf42cd73-linux-amd64.deb \"https:\/\/download.splunk.com\/products\/splunk\/releases\/10.4.2\/linux\/splunk-10.4.2-33c3bf42cd73-linux-amd64.deb\"<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70471\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-03-600x314.jpg\" alt=\"\" width=\"600\" height=\"314\" title=\"\"><\/p>\n<p>Install the Splunk package. Splunk installs to <em>\/opt\/splunk<\/em> by default. Install the <strong>.deb package<\/strong> using <em>dpkg<\/em>.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo dpkg -i splunk-10.4.2-33c3bf42cd73-linux-amd64.deb<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70472\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-04-600x188.jpg\" alt=\"\" width=\"600\" height=\"188\" title=\"\"><\/p>\n<p>Configure Splunk to <strong>start automatically<\/strong> when the system boots. The <em>--accept-license<\/em> flag automatically <strong>agrees to the EULA<\/strong>. During this step, you will be prompted to <strong>create administrative credentials<\/strong> for the Splunk web interface.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo \/opt\/splunk\/bin\/splunk enable boot-start --accept-license<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70473\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-05-600x392.jpg\" alt=\"\" width=\"600\" height=\"392\" title=\"\"><\/p>\n<p>Ensure the <em>splunk<\/em> system user has the <strong>correct read\/write permissions<\/strong> for the installation directory.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo chown -R splunk:splunk \/opt\/splunk<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70474\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-06-600x47.jpg\" alt=\"\" width=\"600\" height=\"47\" title=\"\"><\/p>\n<p>Launch Splunk for the first time running as the <em>splunk<\/em> user.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo -u splunk \/opt\/splunk\/bin\/splunk start<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70475\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-07-600x393.jpg\" alt=\"\" width=\"600\" height=\"393\" title=\"\"><\/p>\n<p>Update the <strong>boot-start configuration<\/strong> to ensure Splunk always launches specifically as the <em>splunk<\/em> user on subsequent reboots.<\/p>\n<p><span style=\"color: #0000ff;\"># sudo \/opt\/splunk\/bin\/splunk enable boot-start -user splunk<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70476\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-08-600x79.jpg\" alt=\"\" width=\"600\" height=\"79\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Install the Veeam App for Splunk<\/h2>\n<p>Access the Splunk web interface at <span style=\"color: #0000ff;\"><em>http:\/\/&lt;IP_Address&gt;:8000<\/em><\/span>. Log in using the <strong>admin credentials<\/strong> you created during the initial setup step.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70477\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-09-600x423.jpg\" alt=\"\" width=\"600\" height=\"423\" title=\"\"><\/p>\n<p>From the main Dashboard, click <strong>Manage<\/strong>\u00a0gear icon.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70478\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-10-600x340.jpg\" alt=\"\" width=\"600\" height=\"340\" title=\"\"><\/p>\n<p>Click <strong>Install App From File<\/strong> in the top-right corner of the screen.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70479\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-11-600x130.jpg\" alt=\"\" width=\"600\" height=\"130\" title=\"\"><\/p>\n<p>Click <strong>Browse<\/strong> to select the Veeam App for Splunk <strong>.tgz file<\/strong> you downloaded earlier, then click <strong>Upload<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70480\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-12-600x296.jpg\" alt=\"\" width=\"600\" height=\"296\" title=\"\"><\/p>\n<p>Once the upload finishes, click <b data-path-to-node=\"14,4,0\" data-index-in-node=\"32\">Close<\/b><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-70481\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-13.jpg\" alt=\"\" width=\"368\" height=\"254\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Configure Data Inputs<\/h2>\n<p>Now that the app is uploaded, you must configure a Data Input to <strong>collect Syslog data<\/strong> from your <a href=\"https:\/\/nolabnoparty.com\/en\/how-to-configure-the-veeam-high-availability-cluster-pt-1\/\">Veeam Backup Server<\/a>.<\/p>\n<p>From the main Dashboard, click <strong>Manage<\/strong> then navigate to <strong>Settings &gt; Data Inputs<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70482\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-14-600x586.jpg\" alt=\"\" width=\"600\" height=\"586\" title=\"\"><\/p>\n<p>Locate the <strong>UDP<\/strong> row in the <strong>Local Inputs<\/strong> section and click <strong>Add new<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70483\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-15-600x271.jpg\" alt=\"\" width=\"600\" height=\"271\" title=\"\"><\/p>\n<p>Select <strong>UDP<\/strong> and specify the <strong>Port<\/strong> you wish to use. In this example, <strong>port 1514<\/strong> is used instead of the <strong>default syslog port 514<\/strong>, as port 514 is often <strong>already in use by Ubuntu<\/strong>'s native logging services. Click <strong>Next<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70484\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-16-600x286.jpg\" alt=\"\" width=\"600\" height=\"286\" title=\"\"><\/p>\n<p>Configure the <strong>Input Settings<\/strong> exactly as follows:<\/p>\n<ul>\n<li><strong>Source type<\/strong> - select <strong>veeam_vbr_syslog<\/strong><\/li>\n<li><strong>App context<\/strong> - select <strong>Veeam App (VeeamApp)<\/strong><\/li>\n<li><strong>Host<\/strong> - select <strong>DNS<\/strong><\/li>\n<li><strong>Index<\/strong> - leave as <strong>Default<\/strong><\/li>\n<\/ul>\n<p>Click <strong>Review<\/strong>\u00a0when done.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70485\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-17-600x456.jpg\" alt=\"\" width=\"600\" height=\"456\" title=\"\"><\/p>\n<p>Verify the settings, and click <strong>Submit<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70486\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-18-600x266.jpg\" alt=\"\" width=\"600\" height=\"266\" title=\"\"><\/p>\n<p>The configuration has been completed successfully.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70487\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-19-600x332.jpg\" alt=\"\" width=\"600\" height=\"332\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Configure Syslog in Veeam Backup &amp; Replication<\/h2>\n<p>To start forwarding events, you must configure your <a href=\"https:\/\/nolabnoparty.com\/en\/veeam-surebackup-on-deduplication-appliances-is-it-a-good-design\/\">Veeam Backup &amp; Replication<\/a> server to <strong>send logs<\/strong> to your Splunk instance.<\/p>\n<p>From the Veeam console, navigate to <strong>Settings &gt; Options<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70488\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-20-600x352.jpg\" alt=\"\" width=\"600\" height=\"352\" title=\"\"><\/p>\n<p>Select the <strong>Event Forwarding<\/strong> tab and click <strong>Add<\/strong> in the <strong>Syslog server<\/strong> section. Enter the <strong>IP Address or DNS name<\/strong> of your Splunk <strong>Server<\/strong> along with the custom port you configured earlier. Ensure the <strong>Transport<\/strong> type is set to <strong>UDP<\/strong>, then click <strong>OK<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-70489\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-21.jpg\" alt=\"\" width=\"530\" height=\"755\" title=\"\"><\/p>\n<p>Click <strong>OK<\/strong> to save and activate the configuration.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-70490\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-22.jpg\" alt=\"\" width=\"530\" height=\"755\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Verify data collection in Splunk<\/h2>\n<p>Return to the Splunk web interface and click <strong>Start Searching<\/strong>.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70491\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-23-600x346.jpg\" alt=\"\" width=\"600\" height=\"346\" title=\"\"><\/p>\n<p>Within a few moments, Splunk will <strong>begin receiving live backup data<\/strong> and populating your dashboard from the Veeam Server.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70492\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-24-600x391.jpg\" alt=\"\" width=\"600\" height=\"391\" title=\"\"><\/p>\n<p>&nbsp;<\/p>\n<h2>Accessing the Dashboard<\/h2>\n<p>To access the Veeam App for Splunk main Dashboard, navigate to the Splunk web interface and <strong>click on the Veeam App icon<\/strong>, which will now be visible in the left-hand navigation pane.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70493\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-25-600x537.jpg\" alt=\"\" width=\"600\" height=\"537\" title=\"\"><\/p>\n<p>Once backup tasks or jobs are executed on your Veeam Server, the data is collected by Splunk and <strong>visually displayed<\/strong> within the app's charts and graphs.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-70494\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/2026\/08\/install-veeam-app-for-splunk-26-600x384.jpg\" alt=\"\" width=\"600\" height=\"384\" title=\"\"><\/p>\n<p>From this point forward, you can <strong>efficiently monitor the status of your entire backup infrastructure<\/strong> from a single pane of glass leveraging the Veeam App for Splunk.<\/p>\n<p><img decoding=\"async\" title=\"signature\" src=\"https:\/\/nolabnoparty.com\/wp-content\/uploads\/images\/firma.jpg\" alt=\"signature\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Veeam App for Splunk is a free solution provided by Veeam to monitor your backup infrastructure by centralizing backup job statuses into a single Dashboard. Depending on your installed Splunk version, the application can be deployed in either a Windows or a Linux environment.<\/p>\n","protected":false},"author":3,"featured_media":70468,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"no","rop_publish_now_accounts":{"facebook_2879994398731222_17841400390232720":"","mastodon_115463926174894442_115463926174894442":"","linkedin_93tdZWzMZc_93tdZWzMZc":"","bluesky_did:plc:tkabz5kl2rukzdwtuongv3kz_did:plc:tkabz5kl2rukzdwtuongv3kz":""},"rop_publish_now_history":[{"account":"facebook_2879994398731222_17841400390232720","service":"facebook","timestamp":1785826836,"status":"queued"},{"account":"linkedin_93tdZWzMZc_93tdZWzMZc","service":"linkedin","timestamp":1787317979,"status":"success"},{"account":"mastodon_115463926174894442_115463926174894442","service":"mastodon","timestamp":1787318009,"status":"success"},{"account":"mastodon_116849603311017847_116849603311017847","service":"mastodon","timestamp":1787318022,"status":"success"},{"account":"twitter_113568041_113568041","service":"twitter","timestamp":1787317991,"status":"error"}],"rop_publish_now_status":"queued","footnotes":""},"categories":[2138,933],"tags":[579,3045,594,584],"class_list":["post-70467","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-backup-en","category-veeam-en","tag-backup-en","tag-monitor-en","tag-splunk-en","tag-veeam-en","has_thumb"],"_links":{"self":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/70467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/comments?post=70467"}],"version-history":[{"count":0,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/posts\/70467\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media\/70468"}],"wp:attachment":[{"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/media?parent=70467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/categories?post=70467"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nolabnoparty.com\/en\/wp-json\/wp\/v2\/tags?post=70467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}