Splunk Cloud Platform

Installing Splunk Add-on for VMware ESXi Logs on Heavy Forwarder

ks17
New Member

Hi Team,

Can we install data collector node on heavy forwarder? what are the care need to be taken on this ?
What are the other services can be installed on the heavy forwarder ? 

 

0 Karma

marnall
Builder

Are you referring to the "Splunk Add-on for VMware"? I believe the "Splunk Add-on for VMware ESXi Logs" only provides Splunk knowledge objects like field extractions.

If so, then yes you can use the heavy forwarder as a data collector node. It defaults to using 10 workers which can be adjusted depending on how much load you expect and how beefy your machine is. I would recommend monitoring the CPU and RAM usage on your heavy forwarder after activating it, to ensure you are within limits.

If you have extra CPU and RAM, then you can also install other apps and services on the heavy forwarder.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...