All Apps and Add-ons

Warning Message from VMWare TA "Input is not proper UTF-8"

hartfoml
Motivator

Any ideas what this warning is telling me?

message from "python /opt/splunk/etc/apps/Splunk_TA_vmware/bin/ta_vmware_collection_scheduler.py" WARNING:splunk.rest.format:There was an error parsing the feed document. Error: Input is not proper UTF-8, indicate encoding

these messages are coming from my indexer not my search head.

PS installed the APP and copied all the VMWare TA's to the indexers. I guess that is right but why would the Collection Scheduler be running on the indexer and should I turn it off?

0 Karma

hartfoml
Motivator

I read throu the documentation and found this link

Component Reference Table

This link told me that the TA above is supposed to be on the indexer but other components should not be loaded on the indexer.

I will remove the components that should not be on the indexers and see if that solves the problem

0 Karma

sd100
Explorer

Have you watched the following video ? https://www.youtube.com/watch?v=GgJUkh0eFH4
the architecture is clearly shown there.

0 Karma

kserra_splunk
Splunk Employee
Splunk Employee

HI Hartformi

The scheduler aspects of the splunk vmware app should be installed on search head which is dedicated to farming out those jobs. There is no reason that these components should be installed on the indexers unless your indexer is also serving as a scheduler (this would not be advised)?

For more detail about these processes see here

http://docs.splunk.com/Documentation/VMW/3.1.4/Configuration/Managedatacollection

0 Karma

hartfoml
Motivator

@kserra_splunk,

Can you help or someone else. I read thru the linked document and I don't think I am having problem with the scheduler only were the scheduler is running from.

In the VMware installation documents it is not so clear to me what parts are put on the search head and what pars are put on the indexers. since all parts are on both indexer and search head it may be that the scheduler is trying to run from the indexer and causing the error message above. I am not sure if I can just delete the scheduler part OR disable the scheduler part.

Is there cleaqr direction anywhere that I have not found that shows what parts of VMWare should be installed on the Searchhead, DCN, Indexer, license manager and Deployment Server.

Splunk has become very expandable but we are no-longer on one Splunk Enterprise System and things should be split up so different jobs are done on different systems.

0 Karma

hartfoml
Motivator

I think your telling me that I don't need the "Splunk_TA_vmware" on the indexer is that right?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...