We are planning for a trial with Splunk Cloud for our Virtual infrastructure, VMware. Could you please assist me with the following questions?
Do I still need to configure individual instances of indexer and search head on my on-premise environment even after deployment of Data Collector Nodes?
After configuration of DCN -VMware addon OVA; would that be enough to forward host syslog data?
Are there any other additional instances that need to be configured in order to forward the vcenter and esxi data to Splunk?
I would really appreciate if you could assist me in the right direction.
I suppose you mean you plan to test the Splunk Cloud product, e.g. https://www.splunk.com/en_us/products/splunk-cloud.html
in that case, when looking at this diagram from docs on app for VMware, http://docs.splunk.com/Documentation/VMW/3.3.2/Installation/Platformandhardwarerequirements
you will want to change the indexer (on the right) to be a Heavy Forwarder that sends all relevant VMware data to the cloud
the apps that supposed to be on indexer are to be installed on HF and the cloud indexer:
Note, it can be sometimes complex to install the app for VMware, therefore it is recommended in docs to always install it first on a test environment and then scale: http://docs.splunk.com/Documentation/VMW/3.3.2/Installation/Planyourinstallation
will also suggest to use Splunk Professional Services for the job
hope it helps.