Getting Data In

Using splunk deployment server to detect virtual containers

tevgey23
Explorer

Can Splunk deployment server detect a container ID in a virtual environment, which was created... say by openvz, and apply the inputs.conf file to that container? This is necessary since the containers keep changing.

Tags (1)
0 Karma

Damien_Dallimor
Ultra Champion

I would say no.

serverclass.conf has whitelist,machineType(deprecated) and machineTypesFilter properties to detect deployment clients.

Perhaps you could set your virtual container's IP addresses to encode the container ID, as described here , and then you can use the whitelist property to setup your serverclass stanzas based on the IP addresses.

0 Karma

tevgey23
Explorer

Currently were using a script within puppet to identify those containers, does the deployment server support such a script. I guess what I can do is pupptize the host, install the forwarder,
and then if its a container Ill add the serverclass and deployment configuration files, from there
the Splunk server can populate the inputs.conf file. Does that sound like something that would work?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...