<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373134#M7820</link>
    <description>&lt;P&gt;Did you try to access those logs as the user Splunk runs at, to make sure it's not a permission issue?&lt;BR /&gt;
If that is fine, try &lt;CODE&gt;/opt/splunkforwarder/bin/splunk list inputstatus&lt;/CODE&gt; to see the status of all of your inputs - you should see your monitor there and also it's status.&lt;/P&gt;</description>
    <pubDate>Thu, 03 May 2018 16:42:27 GMT</pubDate>
    <dc:creator>xpac</dc:creator>
    <dc:date>2018-05-03T16:42:27Z</dc:date>
    <item>
      <title>I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373130#M7816</link>
      <description>&lt;P&gt;05-01-2018 21:56:45.851 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_stats.sh" See '/opt/splunk/etc/apps/ta-dockerstats/bin/docker stats --help'.&lt;BR /&gt;
05-01-2018 21:56:45.851 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_stats.sh" Usage:   docker stats [OPTIONS] CONTAINER [CONTAINER...]&lt;BR /&gt;
05-01-2018 21:56:45.851 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_stats.sh" Display a live stream of container(s) resource usage statistics&lt;BR /&gt;
05-01-2018 21:56:45.872 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_events.sh" Cannot connect to the Docker daemon. Is the docker daemon running on this host?&lt;BR /&gt;
05-01-2018 21:56:46.810 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_events.sh" Cannot connect to the Docker daemon. Is the docker daemon running on this host?&lt;BR /&gt;
05-01-2018 21:56:47.813 +0000 ERROR ExecProcessor - message from "/opt/splunk/etc/apps/ta-dockerstats/bin/docker_events.sh" Cannot connect to the Docker daemon. Is the docker daemon running on this host?&lt;BR /&gt;
05-01-2018 21:56:48.816 +0000 ERROR ExecProcessor - message f&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373130#M7816</guid>
      <dc:creator>vj5</dc:creator>
      <dc:date>2020-09-29T19:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373131#M7817</link>
      <description>&lt;P&gt;The error you're seeing is from the ta-dockerstats addon you can find &lt;A href="https://github.com/splunk/docker-itmonitoring"&gt;here on GitHub&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;This add-on is most likely meant to be run on a docker host, not inside a container. It's supposed to collect statistics about running docker containers etc, so I wonder why this is running inside your container?&lt;/P&gt;

&lt;P&gt;Did you built your Splunk UF container yourself, or are you using a premade one?&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 00:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373131#M7817</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-02T00:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373132#M7818</link>
      <description>&lt;P&gt;Curious, have you seen our solutions for monitoring Docker, Kubernetes and OpenShift clusters? &lt;A href="https://www.outcoldsolutions.com/"&gt;https://www.outcoldsolutions.com/&lt;/A&gt;&lt;BR /&gt;
We also have a blog post explaining how to set up our solution on Tectonic &lt;A href="https://www.outcoldsolutions.com/blog/2018-03-21-monitoring-tectonic-in-splunk/"&gt;https://www.outcoldsolutions.com/blog/2018-03-21-monitoring-tectonic-in-splunk/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 16:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373132#M7818</guid>
      <dc:creator>outcoldman</dc:creator>
      <dc:date>2018-05-03T16:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373133#M7819</link>
      <description>&lt;P&gt;Developers are creating a symlinks to for the application logs in the pods. I want to forward those logs to Splunk using splunk universal forwarder. Here is my inputs.conf. But I don't see any logs forwarded to the splunk UI.&lt;BR /&gt;
Any help is appreciated.&lt;/P&gt;

&lt;P&gt;[monitor:///d/s/r/*.log]&lt;BR /&gt;
host = hostname&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = indexname&lt;BR /&gt;
sourcetype = splunk&lt;BR /&gt;
followSymlink = true &lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 16:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373133#M7819</guid>
      <dc:creator>vj5</dc:creator>
      <dc:date>2018-05-03T16:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373134#M7820</link>
      <description>&lt;P&gt;Did you try to access those logs as the user Splunk runs at, to make sure it's not a permission issue?&lt;BR /&gt;
If that is fine, try &lt;CODE&gt;/opt/splunkforwarder/bin/splunk list inputstatus&lt;/CODE&gt; to see the status of all of your inputs - you should see your monitor there and also it's status.&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2018 16:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373134#M7820</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-03T16:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373135#M7821</link>
      <description>&lt;P&gt;Yes, I am able to access those logs using splunk user. Its now a permission issue. &lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 17:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373135#M7821</guid>
      <dc:creator>vj5</dc:creator>
      <dc:date>2018-05-04T17:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373136#M7822</link>
      <description>&lt;P&gt;@xpac Thanks for your time. I am getting the below output when I am trying /opt/splunkforwarder/bin/splunk list inputstatus this command. Any help is appreciated.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;            /docker/log/containers/d.log
    parent = /docker/log/containers/*.log
    type = broken symlink
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 May 2018 17:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373136#M7822</guid>
      <dc:creator>vj5</dc:creator>
      <dc:date>2018-05-04T17:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373137#M7823</link>
      <description>&lt;P&gt;Yeah, the &lt;CODE&gt;broken symlink&lt;/CODE&gt; says that your... symlink is broken &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;BR /&gt;
You should check with your docker admin who set up that link from the outside into the containers, because it obviously doesn't work. I've too little knowledge on docker to fix that, but if you login as the user Splunk is running as, and do a &lt;CODE&gt;less /docker/log/containers/d.log&lt;/CODE&gt;, you should get an error message, too. Therefore, the file is simply not accessible, which is an OS/filesystem issue, not a Splunk issue.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 18:08:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373137#M7823</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-04T18:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: I am creating a Splunk forwarder docker container to forward the logs to splunk on coreos. I am able to create a container but the logs are not able to forward to the splunk. I see the below error in splunkd.log.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373138#M7824</link>
      <description>&lt;P&gt;when I do less /docker/log/containers/d.log I see output as no such file or directory as output. I see logs are not persistent they are removed or moved every minute or so.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 20:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-am-creating-a-Splunk-forwarder-docker-container-to-forward-the/m-p/373138#M7824</guid>
      <dc:creator>vj5</dc:creator>
      <dc:date>2018-05-04T20:39:41Z</dc:date>
    </item>
  </channel>
</rss>

