Getting Data In

Official support for Splunk 7.3 in Container

vengatesh
New Member

We're considering setting up Splunk enterprise 7.3.0 (for heavy forwarding) in a docker container.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/Systemrequirements
As per this Splunk doc link, the splunk docker image could be used only for evaluation purpose and not officially supported.

Docker images of Splunk Enterprise are also available at Docker Hub for developers to evaluate the deployment of Splunk on containerized infrastructures that are not covered by Splunk support. The community supports these Docker images. See https://hub.docker.com/r/splunk/splunk/.

https://www.splunk.com/en_us/blog/cloud/announcing-splunk-on-docker.html
This Splunk blog says splunk docker image is officially supported.

Can someone confirm whether Splunk enterprise 7.3 docker image (https://hub.docker.com/r/splunk/splunk/) is officially supported?

Thanks!

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.
0 Karma

vengatesh
New Member

Does it mean the Splunk enterprise docker image (7.3) available in https://hub.docker.com/r/splunk/splunk/ is officially supported ?

0 Karma

harsmarvania57
Ultra Champion

Yes if you are running as Single Instance. You can find more information here https://splunk.github.io/docker-splunk/SUPPORT.html

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...