Splunk Enterprise

Transitioning to virtualized servers and validations

danielbb
Motivator

We are in the midst of a virtualization project, and we are looking for a way to sanity check all the different components. I know that the MC does some of it, but I’m not sure if it covers all aspects. I’m thinking about scripted input, and a dedicated dashboard to monitor and verify all the settings. Do you have any other suggestions, by any chance?

Labels (3)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
I’m not sure what you are virtualizing and what you want to monitor or are you asking something else? Are you talking about virtualization of splunk infrastructure or are you monitoring your virtualization environment like VMware?
r. Ismo
0 Karma

danielbb
Motivator

Sorry for not being clear. The process of building these VMs is ongoing, and during this process we would like to be absolutely sure that these VMs are ready to host all the Splunk components. For example. our SE suggested to check the following -

  • THP turned off.
  • All internal logs are being forwarded to indexer tier.
  • MC set-up
  • Splunk running as correct user
  • Splunk restart enabled

So I wonder what would be the best way to ensure that these VMs are built correctly?

I’m thinking about scripted input, and a dedicated dashboard to monitor and verify all the settings. Do you have any other suggestions, by any chance?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...