<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ingesting application logs from Docker container into Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743344#M118099</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm seeking advice on the best way to send application logs from our client's Docker containers into a Splunk Cloud instance, and I’d appreciate your input and experiences.&lt;/P&gt;&lt;P&gt;Currently, my leading approach involves using Docker’s "Splunk logging driver" to forward data via the HEC. However, my understanding is that this method primarily sends container-level data rather than detailed application logs.&lt;/P&gt;&lt;P&gt;Another method I came across involves deploying Splunk's Docker image to create a standalone Enterprise container alongside the Universal Forwarder. The idea here is to set up monitors in the forwarder's inputs.conf to send data to the Enterprise instance and then route it via a Heavy Forwarder to Splunk Cloud.&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented either of these approaches—or perhaps a different method—to ingest application logs from Docker containers into Splunk Cloud? Any insights, tips, or shared experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 01:28:44 GMT</pubDate>
    <dc:creator>tawm_12</dc:creator>
    <dc:date>2025-04-03T01:28:44Z</dc:date>
    <item>
      <title>Ingesting application logs from Docker container into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743344#M118099</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm seeking advice on the best way to send application logs from our client's Docker containers into a Splunk Cloud instance, and I’d appreciate your input and experiences.&lt;/P&gt;&lt;P&gt;Currently, my leading approach involves using Docker’s "Splunk logging driver" to forward data via the HEC. However, my understanding is that this method primarily sends container-level data rather than detailed application logs.&lt;/P&gt;&lt;P&gt;Another method I came across involves deploying Splunk's Docker image to create a standalone Enterprise container alongside the Universal Forwarder. The idea here is to set up monitors in the forwarder's inputs.conf to send data to the Enterprise instance and then route it via a Heavy Forwarder to Splunk Cloud.&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented either of these approaches—or perhaps a different method—to ingest application logs from Docker containers into Splunk Cloud? Any insights, tips, or shared experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 01:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743344#M118099</guid>
      <dc:creator>tawm_12</dc:creator>
      <dc:date>2025-04-03T01:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting application logs from Docker container into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743348#M118100</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274541"&gt;@tawm_12&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We recently completed an integration for one of our customers using the following links:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A href="https://stackoverflow.com/questions/53287922/how-to-forward-application-logs-to-splunk-from-docker-container" target="_blank" rel="noopener"&gt;https://stackoverflow.com/questions/53287922/how-to-forward-application-logs-to-splunk-from-docker-container&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-logging-driver-for-docker.html?_gl=1*1tdlq7k*_gcl_aw*R0NMLjE3NDM1NDMzNzEuQ2owS0NRanduYTZfQmhDYkFSSXNBTElkMlowWjRydUlmV053Nl92U2xyZllHSzdFNTRVeERsbzVTVGJNd2RCaTBqNVZZcERMNERPLVZ0MGFBc1lHRUFMd193Y0I.*_gcl_au*MTY2NzExOTYxOS4xNzQxOTY4Mjky*FPAU*MTY2NzExOTYxOS4xNzQxOTY4Mjky*_ga*MTExNTc3MzM4LjE3NDE5NjgyOTM.*_ga_5EPM2P39FV*MTc0MzY0ODcxMy4yNC4xLjE3NDM2NTAzMDQuMC4wLjMyMDQzNDc5*_fplc*UHpUbnZQWUtQVktCZDF4NUlEb2hibWs1Mm50ZGk0bGpJMDVaVG82Q2huUUNpYXJmRFo4WCUyQk5xeU1IYmE4UzNqM1M0SEx6bG8waFN6S1ZGN2dPenI4dDhZNGltbzRoVVNVMVNteDdEbG5EY29XazhJMzc1S3piNmdsbTFDa2clM0QlM0Q.&amp;amp;locale=en_us" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-logging-driver-for-docker.html?_gl=1*1tdlq7k*_gcl_aw*R0NMLjE3NDM1NDMzNzEuQ2owS0NRanduYTZfQmhDYkFSSXNBTElkMlowWjRydUlmV053Nl92U2xyZllHSzdFNTRVeERsbzVTVGJNd2RCaTBqNVZZcERMNERPLVZ0MGFBc1lHRUFMd193Y0I.*_gcl_au*MTY2NzExOTYxOS4xNzQxOTY4Mjky*FPAU*MTY2NzExOTYxOS4xNzQxOTY4Mjky*_ga*MTExNTc3MzM4LjE3NDE5NjgyOTM.*_ga_5EPM2P39FV*MTc0MzY0ODcxMy4yNC4xLjE3NDM2NTAzMDQuMC4wLjMyMDQzNDc5*_fplc*UHpUbnZQWUtQVktCZDF4NUlEb2hibWs1Mm50ZGk0bGpJMDVaVG82Q2huUUNpYXJmRFo4WCUyQk5xeU1IYmE4UzNqM1M0SEx6bG8waFN6S1ZGN2dPenI4dDhZNGltbzRoVVNVMVNteDdEbG5EY29XazhJMzc1S3piNmdsbTFDa2clM0QlM0Q.&amp;amp;locale=en_us&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 03:22:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743348#M118100</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-04-03T03:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting application logs from Docker container into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743361#M118101</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274541"&gt;@tawm_12&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The simplest method is often configuring your applications within the containers to log to stdout/stderr and then using the Docker Splunk logging driver to forward these logs directly to your Splunk Cloud HEC endpoint.&lt;/P&gt;&lt;P&gt;If your applications &lt;EM&gt;must&lt;/EM&gt; log to files within the container filesystem, you can use a Universal Forwarder (UF) sidecar container.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Method 1: Docker Logging Driver (Recommended if apps log to stdout/stderr)&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Configure your application inside the Docker container to write its logs to standard output (stdout) and standard error (stderr). This is a common practice for containerized applications.&lt;/LI&gt;&lt;LI&gt;Configure the Docker daemon or individual containers to use the splunk logging driver, pointing it to your Splunk Cloud HEC endpoint and token.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;Example docker run command:&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;docker run \
 --log-driver=splunk \
 --log-opt splunk-token= \
 --log-opt splunk-url=https://:8088 \
 --log-opt splunk-format=json \
 --log-opt splunk-verify-connection=false \
 # Add other options like splunk-sourcetype, splunk-index, tag, etc.
 your-application-image&lt;/PRE&gt;&lt;P&gt;This method leverages Docker's built-in logging capabilities. The driver captures the container's stdout/stderr streams (which contain your application logs if configured correctly) and forwards them via HEC.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Method 2: Universal Forwarder Sidecar (If apps log to files)&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Deploy a Splunk Universal Forwarder container alongside your application container.&lt;/LI&gt;&lt;LI&gt;Mount the volume containing the application log files into &lt;EM&gt;both&lt;/EM&gt; the application container (for writing) and the UF container (for reading).&lt;/LI&gt;&lt;LI&gt;Configure the UF container's inputs.conf to monitor the log files within the mounted volume.&lt;/LI&gt;&lt;LI&gt;Configure the UF container's outputs.conf to forward data to your Splunk Cloud HEC endpoint or an intermediate Heavy Forwarder. Using HEC output from the UF is generally preferred for Splunk Cloud.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;EM&gt;Example UF inputs.conf:&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;[monitor:///path/to/mounted/logs/app.log]
sourcetype = your_app_sourcetype
index = your_app_index
disabled = false&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Example UF outputs.conf (for HEC):&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;[httpout]
uri = https://:8088
hecToken = 
# Consider sslVerifyServerCert = true in production after cert setup
sslVerifyServerCert = false
useACK = true

[tcpout:splunk_cloud_forwarder]
server = : # Use if forwarding via UF-&amp;gt;HF-&amp;gt;Splunk Cloud S2S
# Other S2S settings...
# disabled = true # Disable if using httpout&lt;/PRE&gt;&lt;P&gt;The UF actively monitors the specified log files and forwards new events. This is suitable when applications cannot log to &lt;FONT face="Menlo, Monaco, Consolas, Courier New, monospace" color="#c7254e"&gt;&lt;SPAN&gt;stdout&lt;/SPAN&gt;&lt;/FONT&gt;/stderr. The UF sidecar runs in parallel with your app container, sharing the log volume.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The Docker logging driver &lt;/EM&gt;does* send application logs if the application logs are directed to the container's &lt;FONT face="Menlo, Monaco, Consolas, Courier New, monospace" color="#c7254e"&gt;&lt;SPAN&gt;stdout&lt;/SPAN&gt;&lt;/FONT&gt;/stderr.&lt;/P&gt;&lt;UL&gt;&lt;OL&gt;&lt;LI&gt;The approach involving a separate Splunk Enterprise container solely for forwarding is overly complex and not typically recommended. A UF can forward directly or via a standard Heavy Forwarder infrastructure.&lt;/LI&gt;&lt;LI&gt;If you are running in Kubernetes, consider using Splunk Connect for Kubernetes, which streamlines log collection using the OpenTelemetry Collector.&lt;/LI&gt;&lt;LI&gt;Using HEC for sending data to Splunk Cloud. See Splunk Lantern: &lt;A href="https://lantern.splunk.com/Splunk_Platform/Getting_Data_In/Best_Practices_for_Getting_Data_into_Splunk" target="_blank" rel="noopener"&gt;Getting Data In - Best Practices for Getting Data into Splunk&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt; If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding kudos to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Apr 2025 06:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-application-logs-from-Docker-container-into-Splunk/m-p/743361#M118101</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-03T06:20:15Z</dc:date>
    </item>
  </channel>
</rss>

