<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best practice for getting logs from a Docker container into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-getting-logs-from-a-Docker/m-p/214498#M42194</link>
    <description>&lt;P&gt;This pull request was merged into Docker (&lt;A href="https://github.com/docker/docker/pull/16488"&gt;https://github.com/docker/docker/pull/16488&lt;/A&gt;) to add a log driver based on the HTTP Event Collector. &lt;/P&gt;

&lt;P&gt;I'd use either this method or set up logging to the HTTP Event collector direct from your application - we have integrated this with &lt;A href="http://dev.splunk.com/view/splunk-logging-java/SP-CAAAE7M"&gt;Java&lt;/A&gt; and &lt;A href="http://dev.splunk.com/view/splunk-loglib-dotnet/SP-CAAAEX4"&gt;.NET&lt;/A&gt; and in beta for &lt;A href="http://dev.splunk.com/view/splunk-logging-javascript/SP-CAAAE6U"&gt;Javascript&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2015 09:44:50 GMT</pubDate>
    <dc:creator>dart</dc:creator>
    <dc:date>2015-11-06T09:44:50Z</dc:date>
    <item>
      <title>What is the best practice for getting logs from a Docker container into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-getting-logs-from-a-Docker/m-p/214497#M42193</link>
      <description>&lt;P&gt;So, I have about a thousand ways to index logs from a Docker container, but what I'm looking for is some kind of best practice for getting logs from a docker container into splunk.&lt;/P&gt;

&lt;P&gt;None of the solutions I've come up with are elegant and I don't really like them. Anyone out there using Docker and Splunk? If so, how are you accomplishing it? mounting a volume for the container to write logs and then using Splunk on the Docker host? Writing all logs to stdout and forwarding that to Wyslog server that's running a Splunk Forwarder? Running Splunk forwarder inside the container? Something else?&lt;/P&gt;

&lt;P&gt;Help me find a best practice way to do this!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 19:59:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-getting-logs-from-a-Docker/m-p/214497#M42193</guid>
      <dc:creator>jtiner</dc:creator>
      <dc:date>2015-11-05T19:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best practice for getting logs from a Docker container into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-getting-logs-from-a-Docker/m-p/214498#M42194</link>
      <description>&lt;P&gt;This pull request was merged into Docker (&lt;A href="https://github.com/docker/docker/pull/16488"&gt;https://github.com/docker/docker/pull/16488&lt;/A&gt;) to add a log driver based on the HTTP Event Collector. &lt;/P&gt;

&lt;P&gt;I'd use either this method or set up logging to the HTTP Event collector direct from your application - we have integrated this with &lt;A href="http://dev.splunk.com/view/splunk-logging-java/SP-CAAAE7M"&gt;Java&lt;/A&gt; and &lt;A href="http://dev.splunk.com/view/splunk-loglib-dotnet/SP-CAAAEX4"&gt;.NET&lt;/A&gt; and in beta for &lt;A href="http://dev.splunk.com/view/splunk-logging-javascript/SP-CAAAE6U"&gt;Javascript&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 09:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-practice-for-getting-logs-from-a-Docker/m-p/214498#M42194</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2015-11-06T09:44:50Z</dc:date>
    </item>
  </channel>
</rss>

