Getting Data In

Official support for Splunk 7.3 in Container

vengatesh
New Member

We're considering setting up Splunk enterprise 7.3.0 (for heavy forwarding) in a docker container.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/Systemrequirements
As per this Splunk doc link, the splunk docker image could be used only for evaluation purpose and not officially supported.

Docker images of Splunk Enterprise are also available at Docker Hub for developers to evaluate the deployment of Splunk on containerized infrastructures that are not covered by Splunk support. The community supports these Docker images. See https://hub.docker.com/r/splunk/splunk/.

https://www.splunk.com/en_us/blog/cloud/announcing-splunk-on-docker.html
This Splunk blog says splunk docker image is officially supported.

Can someone confirm whether Splunk enterprise 7.3 docker image (https://hub.docker.com/r/splunk/splunk/) is officially supported?

Thanks!

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.
0 Karma

vengatesh
New Member

Does it mean the Splunk enterprise docker image (7.3) available in https://hub.docker.com/r/splunk/splunk/ is officially supported ?

0 Karma

harsmarvania57
Ultra Champion

Yes if you are running as Single Instance. You can find more information here https://splunk.github.io/docker-splunk/SUPPORT.html

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...