Getting Data In

Splunk Cloud & HTTP Event Collector: Docker log-driver error "Failed to initialize logging driver: remote error: handshake failure."

particlebrandon
Explorer

I am using Splunk Cloud with the free trial period right now. I need to verify that we are able to use Splunk Cloud with Docker log-driver before we actually move forward with Splunk long-term. I turned on the HTTP Event Collector in Splunk, but I am not able to pass logs via the Docker log-driver options even with splunk-insecureskipverify set to true. See below.

docker run --log-driver=splunk --log-opt splunk-token=C041DEEB-XXXX-XXX-9F5F-3XXXXXXXXXD1C --log-opt splunk-url=https://input-prd-p-5XXXXXXXXX.cloud.splunk.com:8088 --log-opt splunk-insecureskipverify=true hello-world
docker: Error response from daemon: Failed to initialize logging driver: remote error: handshake failure.

Although I did verify the the HTTP event collector is working with the curl command provided. Although that includes /services/collector in the URL, when that is passed to docker run command, it errors out not expecting it to include the full URI.

barona
Explorer

Did you manage to get docker splunk logging driver work? I'm having exactly the same problem.

0 Karma

micahhausler
Engager

I gave up and went with Fluentd + AWS Cloudwatch Logs + AWS Elasticsearch. Its a breeze to set up

0 Karma

particlebrandon
Explorer

I am ready to give up also, debating on moving back to ELK personally. There was an posting which 1 someone from Splunk mentioned that self-service certs are not supported in golang. I was confused on if that was in Splunk Light or Splunk Cloud or if there was any difference.

At this point I assume there is not any difference and currently Splunk Light/Cloud does not support the docker log-driver.

Sucks because Splunk would have been an perfect fit for me with our logging needs.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...