Splunk Cloud Platform

Installing Splunk Add-on for VMware ESXi Logs on Heavy Forwarder

ks17
New Member

Hi Team,

Can we install data collector node on heavy forwarder? what are the care need to be taken on this ?
What are the other services can be installed on the heavy forwarder ? 

 

0 Karma

marnall
Motivator

Are you referring to the "Splunk Add-on for VMware"? I believe the "Splunk Add-on for VMware ESXi Logs" only provides Splunk knowledge objects like field extractions.

If so, then yes you can use the heavy forwarder as a data collector node. It defaults to using 10 workers which can be adjusted depending on how much load you expect and how beefy your machine is. I would recommend monitoring the CPU and RAM usage on your heavy forwarder after activating it, to ensure you are within limits.

If you have extra CPU and RAM, then you can also install other apps and services on the heavy forwarder.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...