Getting Data In

Splunk Cloud & HTTP Event Collector: Docker log-driver error "Failed to initialize logging driver: remote error: handshake failure."

particlebrandon
Explorer

I am using Splunk Cloud with the free trial period right now. I need to verify that we are able to use Splunk Cloud with Docker log-driver before we actually move forward with Splunk long-term. I turned on the HTTP Event Collector in Splunk, but I am not able to pass logs via the Docker log-driver options even with splunk-insecureskipverify set to true. See below.

docker run --log-driver=splunk --log-opt splunk-token=C041DEEB-XXXX-XXX-9F5F-3XXXXXXXXXD1C --log-opt splunk-url=https://input-prd-p-5XXXXXXXXX.cloud.splunk.com:8088 --log-opt splunk-insecureskipverify=true hello-world
docker: Error response from daemon: Failed to initialize logging driver: remote error: handshake failure.

Although I did verify the the HTTP event collector is working with the curl command provided. Although that includes /services/collector in the URL, when that is passed to docker run command, it errors out not expecting it to include the full URI.

barona
Explorer

Did you manage to get docker splunk logging driver work? I'm having exactly the same problem.

0 Karma

micahhausler
Engager

I gave up and went with Fluentd + AWS Cloudwatch Logs + AWS Elasticsearch. Its a breeze to set up

0 Karma

particlebrandon
Explorer

I am ready to give up also, debating on moving back to ELK personally. There was an posting which 1 someone from Splunk mentioned that self-service certs are not supported in golang. I was confused on if that was in Splunk Light or Splunk Cloud or if there was any difference.

At this point I assume there is not any difference and currently Splunk Light/Cloud does not support the docker log-driver.

Sucks because Splunk would have been an perfect fit for me with our logging needs.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...