<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk docker container limits in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368854#M66982</link>
    <description>&lt;P&gt;Hi epeterfi_splunk,&lt;/P&gt;

&lt;P&gt;There seems to have been a change in the Docker image since my original comment and it now includes the correct license.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.&lt;/P&gt;

&lt;P&gt;Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: &lt;A href="https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html"&gt;https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2017 21:04:49 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2017-11-07T21:04:49Z</dc:date>
    <item>
      <title>Splunk docker container limits</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368851#M66979</link>
      <description>&lt;P&gt;Hello-&lt;BR /&gt;
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this quota not enforced or is there something else I need to do?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 00:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368851#M66979</guid>
      <dc:creator>joshevaughn</dc:creator>
      <dc:date>2017-05-09T00:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk docker container limits</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368852#M66980</link>
      <description>&lt;P&gt;This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in &lt;CODE&gt;At dockercon&lt;/CODE&gt;)  meant to say &lt;CODE&gt;if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day&lt;/CODE&gt; ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 02:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368852#M66980</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-05-09T02:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk docker container limits</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368853#M66981</link>
      <description>&lt;P&gt;Here is the link form the Docker store: &lt;A href="https://store.docker.com/images/splunk"&gt;https://store.docker.com/images/splunk&lt;/A&gt;&lt;BR /&gt;
,Did you sort this out? &lt;BR /&gt;
Here is the link: &lt;A href="https://store.docker.com/images/splunk"&gt;https://store.docker.com/images/splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 11:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368853#M66981</guid>
      <dc:creator>epeterfi_splunk</dc:creator>
      <dc:date>2017-11-07T11:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk docker container limits</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368854#M66982</link>
      <description>&lt;P&gt;Hi epeterfi_splunk,&lt;/P&gt;

&lt;P&gt;There seems to have been a change in the Docker image since my original comment and it now includes the correct license.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.&lt;/P&gt;

&lt;P&gt;Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: &lt;A href="https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html"&gt;https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 21:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-docker-container-limits/m-p/368854#M66982</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-11-07T21:04:49Z</dc:date>
    </item>
  </channel>
</rss>

