<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Indexer as Virtual Machine - Best practices? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138067#M28398</link>
    <description>&lt;P&gt;Has anybody implemented a distributed Splunk Environment using Virtual Machines from top to bottom? &lt;/P&gt;

&lt;P&gt;This seems to be hardly an issue for most of the components, but the Indexer seems to generate the most worry. Are there any resources outlining any unique configuration that would make a virtual Indexer perform better?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Feb 2014 14:05:56 GMT</pubDate>
    <dc:creator>muebel</dc:creator>
    <dc:date>2014-02-05T14:05:56Z</dc:date>
    <item>
      <title>Splunk Indexer as Virtual Machine - Best practices?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138067#M28398</link>
      <description>&lt;P&gt;Has anybody implemented a distributed Splunk Environment using Virtual Machines from top to bottom? &lt;/P&gt;

&lt;P&gt;This seems to be hardly an issue for most of the components, but the Indexer seems to generate the most worry. Are there any resources outlining any unique configuration that would make a virtual Indexer perform better?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2014 14:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138067#M28398</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2014-02-05T14:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexer as Virtual Machine - Best practices?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138068#M28399</link>
      <description>&lt;P&gt;Editor's note: 2014 below. 2016 version here: &lt;A href="https://www.splunk.com/pdfs/technical-briefs/splunk-deploying-vmware-tech-brief.pdf"&gt;https://www.splunk.com/pdfs/technical-briefs/splunk-deploying-vmware-tech-brief.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check out the following Splunk whitepaper:&lt;BR /&gt;
&lt;A href="http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf"&gt;http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2014 21:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138068#M28399</guid>
      <dc:creator>tzeimann</dc:creator>
      <dc:date>2014-09-30T21:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexer as Virtual Machine - Best practices?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138069#M28400</link>
      <description>&lt;P&gt;We started off with our indexers as VM's.  It worked OK in the beginning, as we moved on it turned into a bottle neck. So we ended up buying hardware for the indexers.  Our search heads run fine on a VM.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 23:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138069#M28400</guid>
      <dc:creator>trsavela</dc:creator>
      <dc:date>2014-10-08T23:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexer as Virtual Machine - Best practices?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138070#M28401</link>
      <description>&lt;P&gt;Editor's note: 2014 below. 2016 version here: &lt;A href="https://www.splunk.com/pdfs/technical-briefs/splunk-deploying-vmware-tech-brief.pdf"&gt;https://www.splunk.com/pdfs/technical-briefs/splunk-deploying-vmware-tech-brief.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Check out this URL..&lt;BR /&gt;
&lt;A href="https://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf"&gt;https://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 17:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138070#M28401</guid>
      <dc:creator>jayannah</dc:creator>
      <dc:date>2015-05-08T17:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexer as Virtual Machine - Best practices?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138071#M28402</link>
      <description>&lt;P&gt;Most critical aspects of a successful VM deployment:&lt;BR /&gt;
 - vCPU reservation of at least 8 cores, 12 is better&lt;BR /&gt;
 - vRAM reservation of at least 12GB&lt;BR /&gt;
 - eager-zero provisioned disk providing at least 800IOPS concurrently per indexer&lt;/P&gt;

&lt;P&gt;As long as you don't oversubscribe and configure following the recommendations in the TechBrief, an indexer can work well in a virtual environment. Did I mention resource reservations?&lt;/P&gt;

&lt;P&gt;If your VM hosts are oversubscribed, you don't reserve resources and you are ending up with high CPU Ready counts; or if your underlying disk is not performing at the recommended rates, things will probably not live up to your expectations. &lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2015 18:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Indexer-as-Virtual-Machine-Best-practices/m-p/138071#M28402</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2015-05-08T18:40:01Z</dc:date>
    </item>
  </channel>
</rss>

