Installing App in Distributed Splunk Environment

To install Veeam App for Splunk in a distributed Splunk environment, perform the following steps:

  1. Install Veeam App for Splunk to the indexer cluster and to the search head cluster. For more information, see Install an add-on in a distributed Splunk Enterprise deployment in the Splunk documentation.
  2. Add a new event index with the name veeam to an indexer cluster. For more information, see Create custom indexes in the Splunk documentation.
  3. Configure data inputs for the heavy forwarders:

index = veeam
source_type = veeam_vbr_syslog

For other settings, see Get data from TCP and UDP ports in the Splunk documentation.

To configure the app, log in to Splunk Web on the Splunk instance that performs the role of the deployer for the search head cluster members.

Page updated 2/3/2026

Page content applies to build 2.0.32