Getting Data In

Official support for Splunk 7.3 in Container

vengatesh
New Member

We're considering setting up Splunk enterprise 7.3.0 (for heavy forwarding) in a docker container.

https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/Systemrequirements
As per this Splunk doc link, the splunk docker image could be used only for evaluation purpose and not officially supported.

Docker images of Splunk Enterprise are also available at Docker Hub for developers to evaluate the deployment of Splunk on containerized infrastructures that are not covered by Splunk support. The community supports these Docker images. See https://hub.docker.com/r/splunk/splunk/.

https://www.splunk.com/en_us/blog/cloud/announcing-splunk-on-docker.html
This Splunk blog says splunk docker image is officially supported.

Can someone confirm whether Splunk enterprise 7.3 docker image (https://hub.docker.com/r/splunk/splunk/) is officially supported?

Thanks!

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have a look at https://docs.splunk.com/Documentation/Splunk/7.3.5/Installation/DeployandrunSplunkEnterpriseinsideDo...

Splunk supports single-instance container deployment

We offer support for single-instance Splunk Enterprise and Universal Forwarder containers that run on the following environments:

Splunk software container images only support the Docker runtime engine
We do not support Docker service-level or stack-level configurations, such as swarm clusters or container orchestration.
We do not support complex Splunk Enterprise topologies, including clustering and distributed deployments using container images.
0 Karma

vengatesh
New Member

Does it mean the Splunk enterprise docker image (7.3) available in https://hub.docker.com/r/splunk/splunk/ is officially supported ?

0 Karma

harsmarvania57
Ultra Champion

Yes if you are running as Single Instance. You can find more information here https://splunk.github.io/docker-splunk/SUPPORT.html

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...