Getting Data In

Splunk 5 as VM and using Nimble Storage for shared storage

cgisplunk
Path Finder

Hello everyone,

Does anyone use or know anyone using Splunk 5 in this topology: 2 Splunk indexers (clustered & replicated) running as a VMware VM guest and connecting to Nimble Storage CS220G series storage via iSCSI?
Thank you.
S.

0 Karma
1 Solution

cgisplunk
Path Finder

Almost.
We ended up deploying another Indexer on hardware server, but we'll deploy a search head as a VM with Nimble CS behind it, but again all indexing will be done on a metal local storage box.

View solution in original post

0 Karma

cgisplunk
Path Finder

Almost.
We ended up deploying another Indexer on hardware server, but we'll deploy a search head as a VM with Nimble CS behind it, but again all indexing will be done on a metal local storage box.

0 Karma

cfeskens
Explorer

Thanks for your response. Did you attempt running an indexer on the Nimble CS at all and opt for hardware based on your experiences, or just avoid it alltogether?

0 Karma

cgisplunk
Path Finder

Opted for hardware based on Splunk PS best practices. Bare metal is still the best option for Splunk Indexers.

cfeskens
Explorer

Did you end up attempting this? I'm considering the same setup myself, and would be curious as to your experience.

0 Karma

cgisplunk
Path Finder

Almost.
We ended up deploying another Indexer on hardware server, but we'll deploy a search head as a VM with Nimble CS behind it, but again all indexing will be done on a metal local storage box.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...