Getting Data In

Splunk docker container limits

joshevaughn
New Member

Hello-
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m.

is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 

Is this quota not enforced or is there something else I need to do?

Tags (1)
0 Karma

epeterfi_splunk
Splunk Employee
Splunk Employee

Here is the link form the Docker store: https://store.docker.com/images/splunk
,Did you sort this out?
Here is the link: https://store.docker.com/images/splunk

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi epeterfi_splunk,

There seems to have been a change in the Docker image since my original comment and it now includes the correct license.

creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30

But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.

Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

cheers, MuS

MuS
SplunkTrust
SplunkTrust

This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in At dockercon) meant to say if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day ...

cheers, MuS

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...