Getting Data In

Splunk docker container limits

joshevaughn
New Member

Hello-
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m.

is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 

Is this quota not enforced or is there something else I need to do?

Tags (1)
0 Karma

epeterfi_splunk
Splunk Employee
Splunk Employee

Here is the link form the Docker store: https://store.docker.com/images/splunk
,Did you sort this out?
Here is the link: https://store.docker.com/images/splunk

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi epeterfi_splunk,

There seems to have been a change in the Docker image since my original comment and it now includes the correct license.

creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30

But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.

Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

cheers, MuS

MuS
SplunkTrust
SplunkTrust

This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in At dockercon) meant to say if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day ...

cheers, MuS

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...