Getting Data In

Splunk Indexer as Virtual Machine - Best practices?

muebel
SplunkTrust
SplunkTrust

Has anybody implemented a distributed Splunk Environment using Virtual Machines from top to bottom?

This seems to be hardly an issue for most of the components, but the Indexer seems to generate the most worry. Are there any resources outlining any unique configuration that would make a virtual Indexer perform better?

s2_splunk
Splunk Employee
Splunk Employee

Most critical aspects of a successful VM deployment:
- vCPU reservation of at least 8 cores, 12 is better
- vRAM reservation of at least 12GB
- eager-zero provisioned disk providing at least 800IOPS concurrently per indexer

As long as you don't oversubscribe and configure following the recommendations in the TechBrief, an indexer can work well in a virtual environment. Did I mention resource reservations?

If your VM hosts are oversubscribed, you don't reserve resources and you are ending up with high CPU Ready counts; or if your underlying disk is not performing at the recommended rates, things will probably not live up to your expectations.

jayannah
Builder
0 Karma

trsavela
Path Finder

We started off with our indexers as VM's. It worked OK in the beginning, as we moved on it turned into a bottle neck. So we ended up buying hardware for the indexers. Our search heads run fine on a VM.

0 Karma

tzeimann
Engager
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...