Getting Data In

Splunk docker container limits

joshevaughn
New Member

Hello-
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m.

is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 

Is this quota not enforced or is there something else I need to do?

Tags (1)
0 Karma

epeterfi_splunk
Splunk Employee
Splunk Employee

Here is the link form the Docker store: https://store.docker.com/images/splunk
,Did you sort this out?
Here is the link: https://store.docker.com/images/splunk

0 Karma

MuS
Legend

Hi epeterfi_splunk,

There seems to have been a change in the Docker image since my original comment and it now includes the correct license.

creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30

But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.

Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

cheers, MuS

MuS
Legend

This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in At dockercon) meant to say if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day ...

cheers, MuS

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...