Installation

Clarify UF install process for VDI environment

aborgna512
Explorer

I'm looking for some clarity about the recommended process for installing UFs in a VDI environment (e.g. Azure Virtual Desktop, VMWare Horizon, etc.). I'm familiar with the host image install and clone process that is outlined in the splunk docs link below. Is this process recommended for deploying VDIs? Install on the parent VDI and clone down to the child VDI sessions. Please advise if there are any special considerations for VDI vs. traditional VM creation/deployment.

Integrate a universal forwarder onto a system image - Splunk Documentation

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

install the UF on the VDI the same way you would install it on any other computer running the same platform.

If you're creating a template that will be used to create additional VDIs then, yes, follow the linked instructions to make sure each UF has a unique GUID.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

aborgna512
Explorer

Thank you Rich for the feedback. We plan to start small and scale out with VDIs in the long run. The image template is what we are working on to be able to quickly deploy VDIs with installed UFs to meet our needs. I appreciate the swift response.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

install the UF on the VDI the same way you would install it on any other computer running the same platform.

If you're creating a template that will be used to create additional VDIs then, yes, follow the linked instructions to make sure each UF has a unique GUID.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...