Getting Data In

How to install and configure a universal forwarder on servers that are running applications in a Docker container?

AzmathShaik
Path Finder

Hello

i was looking at Splunk docs regarding how to install Splunk forwarder and configure inputs to forward logs from Docker container. Unluckily, I could not find any thing. Can any one help me in what is the process to install and read logs from Docker container??

Thanks in advance

0 Karma

tormodbp
Path Finder

Hi,

Before I present you some possible links for further reading, I must state that I have not done this myself yet.

Back in 2015 Splunk blog had a development blog entry about "Integrating Splunk with Docker, CoreOS and JournalID".
In the blog post it explains how to integrate a universal forwarder into an environment where all applications are run in docker containers, and thus do not support regular installation of a forwarder. Docker container used for the Splunk forwarder is publicly available in the Docker hub. Source is available on Github.

I believe that the above mentioned blogpost would assist you in your problem.

Sorry that I could not assist you further with a solution.

Cheers,

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...