Splunk® App for VMware (Legacy)

Installation and Configuration Guide

Acrobat logo Download manual as PDF


On August 31, 2022, the Splunk App for VMware will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for VMware Dashboards and Reports.
This documentation does not apply to the most recent version of Splunk® App for VMware (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Considerations

As we have discussed, there are two primary ways to scale the Solution:

  • Run multiple engines within a single FA.
  • Deploy multiple FAs, possibly with multiple engines running in each one.

To write an engine.conf file or to split the engine file across many FA VM(s) and engine instances to support your environment, you must consider the following:

  1. How large is your environment? Knowing the size of your environment (the number of hosts and VMs) helps to determine the number of forwarder appliances you need to monitor these hosts. it also helps determine the length of time it will take to run the actions that collect the data from your environment. For examle, the collection of inventory data can take a very long time in a very large environment. Knowing the number of hosts, the number of virtual centers, and the number of virtual machines can help you determine how you want to monitoring your virtual environment.
  2. How much volatility is in your environment? In an environment where virtual machines are quickly created and deleted, you may need to increase the data collection frequency for Splunk to capture certain kinds of data. Setting up the correct frequency for data collection assists in getting data in as fast as possible and ensuring the complete data sets are collected.
  3. How close to "real-time" do your need to monitor your environment? If you need to detect changes in your environment in "real-time (immediately), you can increase the frequency of collection to ensure that Splunk sees the changes in the data. Setting up the correct frequency for data collection assists in getting data in as fast as possible.
  4. How critical is the data you are collecting? Is the collection of performance metrics critical to your environment? Give critical data special treatment in the forwarder appliances. Identify data that has highest priority and make sure that it is collected at the correct frequency (fast enough to get it all in).
Last modified on 14 September, 2012
PREVIOUS
Your environment
  NEXT
Recommendations

This documentation applies to the following versions of Splunk® App for VMware (Legacy): 1.0, 1.0.1, 1.0.2, 1.0.3, 2.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters