Splunk Search

splunk in virtual machine

kml_uvce
Builder

I read in splunk doc that we should not use splunk in virtual machine because splunk require more input and outpur.
But still can we use virtual machine for splunk for any task?

Tags (1)
1 Solution

Ayn
Legend

I don't know where it says that you shouldn't use Splunk in a VM at all? While it's true that there are considerations to make when deploying Splunk on virtual machines, there's nothing stopping you from taking that route. Splunk (the company) themselves even run their main Splunk (the product) installation in VMs (see http://blogs.splunk.com/2012/02/28/splunkx-splunking-the-enterprise/ and http://blogs.splunk.com/2012/03/14/the-splunkx-environment/ ).

More information on things to consider when deploying Splunk in virtual machines: http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf

View solution in original post

Ayn
Legend

I don't know where it says that you shouldn't use Splunk in a VM at all? While it's true that there are considerations to make when deploying Splunk on virtual machines, there's nothing stopping you from taking that route. Splunk (the company) themselves even run their main Splunk (the product) installation in VMs (see http://blogs.splunk.com/2012/02/28/splunkx-splunking-the-enterprise/ and http://blogs.splunk.com/2012/03/14/the-splunkx-environment/ ).

More information on things to consider when deploying Splunk in virtual machines: http://www.splunk.com/web_assets/pdfs/secure/Splunk_and_VMware_VMs_Tech_Brief.pdf

kristian_kolb
Ultra Champion

Also, there is a big difference between installing a full Splunk server on a VM (for the reasons mentioned above), and installing a forwarder on a virtual host sending the logs elsewhere, which is perfectly fine under almost any circumstance.

/k

0 Karma

Drainy
Champion

All about size and scale..

dwaddle
SplunkTrust
SplunkTrust

Echoing Ayn's advice - it's all about scale and sizing. Most people oversubscribe their VM estate - especially with the number of network / disk I/O paths per guest. Splunk (like any other I/O intensive application) can suffer poor performance when the VM environment isn't sized properly or to too far oversubscribed.

ftk
Motivator

As long as you can give Splunk the disk IO and memory it needs it runs just fine in a VM. Perfect for Dev system.

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...