Getting Data In

Official support for Splunk 7.3 in Container

vengatesh
New Member

We're considering setting up Splunk enterprise 7.3.0 (for heavy forwarding) in a docker container.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/Systemrequirements
As per this Splunk doc link, the splunk docker image could be used only for evaluation purpose and not officially supported.

Docker images of Splunk Enterprise are also available at Docker Hub for developers to evaluate the deployment of Splunk on containerized infrastructures that are not covered by Splunk support. The community supports these Docker images. See https://hub.docker.com/r/splunk/splunk/.

https://www.splunk.com/en_us/blog/cloud/announcing-splunk-on-docker.html
This Splunk blog says splunk docker image is officially supported.

Can someone confirm whether Splunk enterprise 7.3 docker image (https://hub.docker.com/r/splunk/splunk/) is officially supported?

Thanks!

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.
0 Karma

vengatesh
New Member

Does it mean the Splunk enterprise docker image (7.3) available in https://hub.docker.com/r/splunk/splunk/ is officially supported ?

0 Karma

harsmarvania57
Ultra Champion

Yes if you are running as Single Instance. You can find more information here https://splunk.github.io/docker-splunk/SUPPORT.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...