Getting Data In

Splunk Cloud & HTTP Event Collector: Docker log-driver error "Failed to initialize logging driver: remote error: handshake failure."

particlebrandon
Explorer

I am using Splunk Cloud with the free trial period right now. I need to verify that we are able to use Splunk Cloud with Docker log-driver before we actually move forward with Splunk long-term. I turned on the HTTP Event Collector in Splunk, but I am not able to pass logs via the Docker log-driver options even with splunk-insecureskipverify set to true. See below.

docker run --log-driver=splunk --log-opt splunk-token=C041DEEB-XXXX-XXX-9F5F-3XXXXXXXXXD1C --log-opt splunk-url=https://input-prd-p-5XXXXXXXXX.cloud.splunk.com:8088 --log-opt splunk-insecureskipverify=true hello-world
docker: Error response from daemon: Failed to initialize logging driver: remote error: handshake failure.

Although I did verify the the HTTP event collector is working with the curl command provided. Although that includes /services/collector in the URL, when that is passed to docker run command, it errors out not expecting it to include the full URI.

barona
Explorer

Did you manage to get docker splunk logging driver work? I'm having exactly the same problem.

0 Karma

micahhausler
Engager

I gave up and went with Fluentd + AWS Cloudwatch Logs + AWS Elasticsearch. Its a breeze to set up

0 Karma

particlebrandon
Explorer

I am ready to give up also, debating on moving back to ELK personally. There was an posting which 1 someone from Splunk mentioned that self-service certs are not supported in golang. I was confused on if that was in Splunk Light or Splunk Cloud or if there was any difference.

At this point I assume there is not any difference and currently Splunk Light/Cloud does not support the docker log-driver.

Sucks because Splunk would have been an perfect fit for me with our logging needs.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...