icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading EMC XtremIO App for Splunk Enterprise
SHA256 checksum (emc-xtremio-app-for-splunk-enterprise_110.tgz) b9656dd731738c596e991de9dfc4423b126aae638e75285976f2a22ac4134ac1 SHA256 checksum (emc-xtremio-app-for-splunk-enterprise_10.tgz) 52714bd984288f3f8eacb0a0b8e7ec23b5fe6abbdca90d3c4d6910ea09383afa
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


EMC XtremIO App for Splunk Enterprise

Splunk Cloud
This app is NOT supported by Splunk. Please read about what that means for you here.
The EMC XtremIO App for Splunk Enterprise gathers the data from EMC XtremIO cluster and allows the splunk Enterprise administrator to:

* moitor the cluster inventory
* monitor the cluster performance parameters like bandwidhth,Latency and
* monitor the critical events generated in a XtremIO cluster.


The EMC XtremIO App for Splunk Enterprise allows a SplunkĀ® Enterprise administrator to gain insight of XtremIO Cluster inventory and performance data.

  • Author - Crest Data Systems

  • Version - 1.0

  • Compatible products - EMC XtremIO 2.4 and later

  • Creats Index - False

  • Implements summarization - False

About this release

  • Compatible with:

    Splunk Enterprise version : 6.2.3

    EMC XtremIO 2.4 and later

    OS : platform independent



  • Splunk version 6.2.3

Recommended System configuration

  • Splunk search head system should have 8 GB of RAM and a quad-core CPU to run this app smoothly.

Topology and Setting up Splunk Environment

  • This app has been distributed in two parts.

1) Add-on app, which runs collector scripts and gathers data from EMC XtremIO cluster, does
indexing on it and provides indexed data to Main app.

2) Main app, which receives indexed data from Add-on app, runs searches on it and builds
dashboard using indexed data.

  • This App can be set up in two ways:
Deploy to single server instance

Standalone Mode: Install main app and Add-on app on a single machine.

 * Here both the app resides on a single machine.
 * Main app uses the data collected by Add on app and builds dashboard on it
Deploy to distributed deployment

Distributed Environment: Install main app and Add-on app on Indexer and only Add-on app on forwarder system.

 * Here also both the apps resides on Indexer machine.
 * Only Add-on app required to be installed on forwarder system.
 * Execute the following command to forward the collected data to the Indexer.
   /opt/splunk/bin/splunk add forward-server <indexer_ip_address>:9997
 * On Indexer machine, enable the event listening on port 9997 (recommended by Splunk).
 * Main app on search head/Indexer uses the received data and builds dashboard on it.


Download the EMC XtemIO App for Splunk Enterprise at https://splunkbase.splunk.com/app/2812.

Installation Steps

  • This app can be installed either through UI through "Manage Apps" or by extracting zip file into $SPLUNK_HOME$/etc/apps folder.
  • Restart Splunk


  • Sourcetypes: emc:xtremio:rest

  • Lookups : XtremIOClusterNameLookup, XtremIOClustersLookup, XtremIOVolumesLookup,
    XtremIOxBricksLookup, XtremIOInitiatorsLookup, XtremIOTargetsLookup,
    XtremIOSnapshotsLookup, XtremIOStorageControllersLookup, XtremIOSSDsLookup


This App contains following lookup files.


  • This lookup maintains mapping of XtremIO server node ip and Clsuter Name

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOClusterName.csv

  • Lookup fields: "Cluster Name","XtremIO_Server"


  • This lookup maintains summary and inventory related data for each configured XtremIO Cluster

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOClusters.csv

  • Lookup fields: "Cluster Name",Index,"Compression Mode","System State","Target Group Count","Target Count","SSD Count","BBU Count","Volume Count","xEnv Count","Controller Count","xBricks Count","Infiniband Switch Count","Dedup Ratio","Physical Space In Use","Logical Space In Use","System Start Time","License Id","XIOS Version",Health,Bandwidth,Latency,IOPS,"Compression Factor","Overall Efficiency","Thin Provisioning Savings","Total Capacity"


  • This lookup maintains summary and inventory related data for each XtremIO Cluster Volume

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOVolumes.csv

  • Lookup fields: "Cluster Name","Volume Name",Compressible,"Logical Block Size","Small IO Alerts",Index,"Creation Timestamp","Logical Space Used","Volume Size","Total Snaps","Total Lun Mappings","VAAI TP Alerts",Bandwidth,Latency,IOPS


  • This lookup maintains summary and inventory related data for each XtremIO xBrick

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOxBricks.csv

  • Lookup fields: "Cluster Name","Brick Name",Index,"Node Count","SSD Count",GUID,State


  • This lookup maintains summary and inventory related data for each XtremIO Initiator

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOInitiators.csv

  • Lookup fields: "Cluster Name","Initiator Name",Index,Bandwidth,Latency,IOPS,"Group Name","Port Address","Port Type","Connection State","Connected Targets"


  • This lookup maintains summary and inventory related data for each XtremIO Target

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOTargets.csv

  • Lookup fields: "Cluster Name","Target Name",Index,"Jumbo Frame Enabled","Driver Version","Brick Name","Storage Controller",Bandwidth,Latency,IOPS,"Port Address","Port Type","Port State"


  • This lookup maintains summary and inventory related data for each XtremIO Snapshot

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOSnapshots.csv

  • Lookup fields: "Cluster Name","XtremIO_Server"


  • This lookup maintains summary and inventory related data for each XtremIO storage controller

  • File location: $SPLUNK_HOME$/etc/apps/EMC-app-XtremIO/lookups/XtremIOStorageControllers.csv

  • Lookup fields: "Cluster Name","Brick Name","Controller Name",Index,"Local Disk Count","PSU Count","SSD Count",Health,"Firmware Version","OS Version","IB1 Address","IB2 Address","IB1 Port State","IB2 Port State","IB1 Port Type","IB2 Port Type","IB1 link health","IB2 link health"

Configure App

  • This App doesn't need any configuration steps.Plese refer the documentation of "EMC XtremIO
    Add-on for Splunk Enterprise" to see how to set up the Add-on app.

Release Notes

Version 1.1.0
Aug. 3, 2021

Added compatibility with latest Splunk versions

Version 1.0
July 31, 2015

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.