Getting Data In

Splunk docker container limits

joshevaughn
New Member

Hello-
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m.

is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 

Is this quota not enforced or is there something else I need to do?

Tags (1)
0 Karma

epeterfi_splunk
Splunk Employee
Splunk Employee

Here is the link form the Docker store: https://store.docker.com/images/splunk
,Did you sort this out?
Here is the link: https://store.docker.com/images/splunk

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi epeterfi_splunk,

There seems to have been a change in the Docker image since my original comment and it now includes the correct license.

creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30

But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.

Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

cheers, MuS

MuS
SplunkTrust
SplunkTrust

This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in At dockercon) meant to say if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day ...

cheers, MuS

Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...