All Apps and Add-ons

VMware App 3.0 performance data not collected

ivanhoe
New Member

In a test VMware environment, I installed the VMware App 3.0 but I have an issue with Data Collection node, because it is not collecting performance data, It seems that the hierarchy collection is unstable because it gathers hierarchy information not continuously.

0 Karma

ivanhoe
New Member

According to the panels on Install Health dashboard, hierarchy data comes in. I can see on top that every channel work fine, including Collection Node, ESXi host log input, listening on port UDP 514 and vCenter forwarder.
The three counters show no data from performance TSIDX namespace.

0 Karma

dart
Splunk Employee
Splunk Employee

A few problems I have seen in deployments of the VMWare app:

  1. Data Collection Node not set to forward to your indexers
  2. Hydra Workers not having all roles enabled

What do the health views contain in the app?

0 Karma

cmeo
Contributor

What does 'Hydra Workers not having all roles enabled' mean? This isn't in the docs and isn't explained anywhere else. What are these roles and how do you manipulate them? I have a customer with what appears to be the same problem in this app. Platform is Windows, Splunk v6. We certainly saw problem #1, the installation didn't set this either.

0 Karma

ivanhoe
New Member

20 host are covered by vCenter machine.
In the group there are around 160 VM and I am currently using only one collection node.

0 Karma

abhide_splunk
Splunk Employee
Splunk Employee

Can you give me an idea of how your environment is resourced, how many hosts, VMs, how many data collection nodes?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...