<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Install Splunk Universal Forwarder into OpenShift platform in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82983#M17220</link>
    <description>&lt;P&gt;I tried googling it but without any luck, also I tried searching official mailing lists, but also without any information.&lt;/P&gt;

&lt;P&gt;Is it possible to install Splunk Universal Forwarder to OpenShift platform?&lt;/P&gt;

&lt;P&gt;Maybe create our own custom cartridge?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2013 11:10:27 GMT</pubDate>
    <dc:creator>MicTech</dc:creator>
    <dc:date>2013-04-03T11:10:27Z</dc:date>
    <item>
      <title>Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82983#M17220</link>
      <description>&lt;P&gt;I tried googling it but without any luck, also I tried searching official mailing lists, but also without any information.&lt;/P&gt;

&lt;P&gt;Is it possible to install Splunk Universal Forwarder to OpenShift platform?&lt;/P&gt;

&lt;P&gt;Maybe create our own custom cartridge?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2013 11:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82983#M17220</guid>
      <dc:creator>MicTech</dc:creator>
      <dc:date>2013-04-03T11:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82984#M17221</link>
      <description>&lt;P&gt;I also have been trying to do this and I would appreciate any insights. &lt;/P&gt;</description>
      <pubDate>Sun, 08 Feb 2015 18:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82984#M17221</guid>
      <dc:creator>homerotl</dc:creator>
      <dc:date>2015-02-08T18:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82985#M17222</link>
      <description>&lt;P&gt;is there any solution on this?&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 07:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82985#M17222</guid>
      <dc:creator>edwren</dc:creator>
      <dc:date>2015-05-22T07:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82986#M17223</link>
      <description>&lt;P&gt;I too am looking for a Splunk forwarder for Open Shift.  &lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 20:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82986#M17223</guid>
      <dc:creator>opetopet</dc:creator>
      <dc:date>2015-06-18T20:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82987#M17224</link>
      <description>&lt;P&gt;Shouldnt it work by installing from source vs rpm?&lt;/P&gt;

&lt;P&gt;Copy the tarball to your OpenShift server, extract, change the permissions, run splunk...&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 09:55:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82987#M17224</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2015-11-06T09:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82988#M17225</link>
      <description>&lt;P&gt;forgive me I have 0 experience with openShift.  I do run splunk on RHEL in AWS often though.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 09:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82988#M17225</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2015-11-06T09:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82989#M17226</link>
      <description>&lt;P&gt;Openshift is another type of container just like Docker.  I would not recommend trying to install a forwarder in Openshift but instead use &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE6M"&gt;Splunk's HTTP event collector&lt;/A&gt;.  Rather than trying to wrote to a log have your application send logs directly to the HTTP event collector.  Possible set up a queueing service like zmq or sqs which your application log too directly and have splunk poll the queue.  This is great for ephemeral services and servers. &lt;/P&gt;

&lt;P&gt;Of course this will require some dev time.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 23:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82989#M17226</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-11-10T23:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82990#M17227</link>
      <description>&lt;P&gt;Given OpenShift v3 now supports Docker - &lt;A href="https://blog.openshift.com/openshift-v3-platform-combines-docker-kubernetes-atomic-and-more/"&gt;https://blog.openshift.com/openshift-v3-platform-combines-docker-kubernetes-atomic-and-more/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The blog "Collecting docker logs and stats with Splunk" - &lt;A href="http://blogs.splunk.com/2015/08/24/collecting-docker-logs-and-stats-with-splunk/"&gt;http://blogs.splunk.com/2015/08/24/collecting-docker-logs-and-stats-with-splunk/&lt;/A&gt; may be a good starting point for you as it includes how to install a Splunk forwarder on Docker.&lt;/P&gt;

&lt;P&gt;Also there is the recently released "Splunk logging driver" for Docker - &lt;A href="https://docs.docker.com/engine/admin/logging/splunk/"&gt;https://docs.docker.com/engine/admin/logging/splunk/&lt;/A&gt; for Docker which uses the HTTP event collector which may be an alternative for you. A blog introducing it can be found at &lt;A href="http://blogs.splunk.com/2015/12/16/splunk-logging-driver-for-docker/"&gt;http://blogs.splunk.com/2015/12/16/splunk-logging-driver-for-docker/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 14:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82990#M17227</guid>
      <dc:creator>msivill_splunk</dc:creator>
      <dc:date>2016-03-22T14:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82991#M17228</link>
      <description>&lt;P&gt;Hi MicTech,&lt;/P&gt;

&lt;P&gt;OpenShift v3 is based on Kubernetes and includes the same default logging layer (Fluentd). Fluentd can send messages to Splunk with some community-built plugins that will need to be configured for sending to either the Splunk API, HTTP Event Collector, or TCP receiver. &lt;/P&gt;

&lt;P&gt;Documentation for the latest version (3) of OpenShift about logging, and configuring the specific output can be found here:&lt;BR /&gt;
&lt;A href="https://docs.openshift.com/enterprise/3.1/install_config/aggregate_logging.html"&gt;https://docs.openshift.com/enterprise/3.1/install_config/aggregate_logging.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Treasure Data also offers Fluentd Enterprise that has a supported Splunk plugins for the HTTP Event Collector and over TCP. More information can be found on &lt;A href="https://fluentd.treasuredata.com"&gt;https://fluentd.treasuredata.com&lt;/A&gt; or email me at a @ treasuredata.com&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Anurag&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jul 2017 22:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82991#M17228</guid>
      <dc:creator>agup006</dc:creator>
      <dc:date>2017-07-02T22:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82992#M17229</link>
      <description>&lt;P&gt;We have developed an application for Monitoring OpenShift clusters, including forwarding logs (container, host and openshift components) and monitoring stats (CPU, Memory, IO, etc) on level of processes, containers, pods, hosts. You can get the application from Splunkbase &lt;A href="https://splunkbase.splunk.com/app/3836/"&gt;https://splunkbase.splunk.com/app/3836/&lt;/A&gt; and find installation instructions on this page &lt;A href="https://www.outcoldsolutions.com/docs/monitoring-openshift/"&gt;https://www.outcoldsolutions.com/docs/monitoring-openshift/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2018 06:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82992#M17229</guid>
      <dc:creator>outcoldman</dc:creator>
      <dc:date>2018-01-06T06:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82993#M17230</link>
      <description>&lt;P&gt;msivill, I have tried to configure splunk-logging-driver-for-docker as you suggested.  It worked like a charm.  But,  it stops working as soon as OpenShift gets added to the mix.  Reading OpenShift source code ... got complex and "hairy in a hurry."  &lt;/P&gt;

&lt;P&gt;If anyone has any real-world implementations of the Splulnk App suggested by  outcoldman,  I would love to hear your thoughts.   PM is ok.&lt;/P&gt;

&lt;P&gt;Y.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 02:10:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82993#M17230</guid>
      <dc:creator>yarick</dc:creator>
      <dc:date>2018-04-06T02:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk Universal Forwarder into OpenShift platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82994#M17231</link>
      <description>&lt;P&gt;As a POC, I have been able to get the Splunk forwarder working but it requires a lot of tweaking (def. not enterprise ready). &lt;/P&gt;

&lt;P&gt;Basically I followed this guide: &lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Makeauniversalforwarderpartofahostimage"&gt;https://docs.splunk.com/Documentation/Forwarder/7.2.6/Forwarder/Makeauniversalforwarderpartofahostimage&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In order for this to work, here are the things I did:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;On a separate machine with Docker (not OpenShift), create a Dockerfile or use the one on github: &lt;A href="https://github.com/splunk/docker-splunk/blob/develop/splunk/common-files/Dockerfile"&gt;https://github.com/splunk/docker-splunk/blob/develop/splunk/common-files/Dockerfile&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Get it working, then run the command to clear clone-prep-clear-config command: ./splunk clone-prep-clear-config&lt;/LI&gt;
&lt;LI&gt;Use the docker cp command to copy the etc, var, and share from $SPLUNK_HOME&lt;/LI&gt;
&lt;LI&gt;Zip those directories.&lt;/LI&gt;
&lt;LI&gt;In OpenShift, add persistent storage for the etc, var and share paths as volumes&lt;/LI&gt;
&lt;LI&gt;In my entrypoint.sh file (Just did it here as testing), I added some logic to populate etc, var and share paths with the zips created in step 4.&lt;/LI&gt;
&lt;LI&gt;Start service.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Note: I running this as a side-car solution where I have the app in the same project. The app is writing logs to another persistent volume that is shared with the splunk-forwarder pod and splunk-forwarder is configured to read from that persistent volume. &lt;/P&gt;

&lt;P&gt;Going forward we're going to look at fluentd forwarding logs to splunk. &lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 21:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Install-Splunk-Universal-Forwarder-into-OpenShift-platform/m-p/82994#M17231</guid>
      <dc:creator>jimmyliangdca</dc:creator>
      <dc:date>2019-05-22T21:07:39Z</dc:date>
    </item>
  </channel>
</rss>

