All Apps and Add-ons

Questions regarding configuring Splunk Cloud with VMware

nchhe001
New Member

We are planning for a trial with Splunk Cloud for our Virtual infrastructure, VMware. Could you please assist me with the following questions?

  1. Do I still need to configure individual instances of indexer and search head on my on-premise environment even after deployment of Data Collector Nodes?

  2. After configuration of DCN -VMware addon OVA; would that be enough to forward host syslog data?

  3. Are there any other additional instances that need to be configured in order to forward the vcenter and esxi data to Splunk?

I would really appreciate if you could assist me in the right direction.

Thanks
Nikhil Chhetri

0 Karma

adonio
Ultra Champion

hello there,
I suppose you mean you plan to test the Splunk Cloud product, e.g. https://www.splunk.com/en_us/products/splunk-cloud.html
in that case, when looking at this diagram from docs on app for VMware, http://docs.splunk.com/Documentation/VMW/3.3.2/Installation/Platformandhardwarerequirements
you will want to change the indexer (on the right) to be a Heavy Forwarder that sends all relevant VMware data to the cloud
the apps that supposed to be on indexer are to be installed on HF and the cloud indexer:
http://docs.splunk.com/Documentation/VMW/3.3.2/Installation/DownloadandinstalltheSplunkAppforVMware
Note, it can be sometimes complex to install the app for VMware, therefore it is recommended in docs to always install it first on a test environment and then scale: http://docs.splunk.com/Documentation/VMW/3.3.2/Installation/Planyourinstallation
will also suggest to use Splunk Professional Services for the job
hope it helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...