Getting Data In

Splunk docker container limits

joshevaughn
New Member

Hello-
At dockercon I was made aware of the splunk docker container from the docker store. According to the documentation posted there, we should be able to index 20g of logs a day, however the license that is installed is only good for 500m.

is_unlimited    False
label   Splunk Enterprise + Hunk Download Trial
max_violations  5
payload     None
quota_bytes     524288000.0
sourcetypes     

stack_name  download-trial
status  VALID
type    download-trial 

Is this quota not enforced or is there something else I need to do?

Tags (1)
0 Karma

epeterfi_splunk
Splunk Employee
Splunk Employee

Here is the link form the Docker store: https://store.docker.com/images/splunk
,Did you sort this out?
Here is the link: https://store.docker.com/images/splunk

0 Karma

MuS
Legend

Hi epeterfi_splunk,

There seems to have been a change in the Docker image since my original comment and it now includes the correct license.

creation_time   2016-09-26 17:37:17+00:00
expiration_time 2018-11-07 20:46:38+00:00
features    
Acceleration
AdvancedSearchCommands
AdvancedXML
Alerting
Auth
CustomRoles
DeployClient
DeployServer
FwdData
GuestPass
KVStore
LocalSearch
NontableLookups
RcvData
RollingWindowAlerts
SAMLAuth
ScheduledAlerts
ScheduledReports
ScheduledSearch
ScriptedAuth
SigningProcessor
SplunkWeb
SyslogOutputProcessor
hash    6250D4DA1BB11EC718586A639E419C8314F90BD035B377EFF109DF742916204E
label   Splunk Enterprise Free for docker
max_violations  5
payload None
quota_bytes 21474836480.0
sourcetypes 
stack_name  download-trial
status  VALID
type    download-trial
window_period   30

But downvoting should only be reserved for suggestions/solutions that could be potentially harmful for a Splunk environment or goes completely against known best practices.

Before engaging further in voting people's posts, read how voting etiquette works in Splunk Answers: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

cheers, MuS

MuS
Legend

This is a Splunk Enterprise trail version, which by default has the 500Mb license. Maybe they (As in At dockercon) meant to say if you have a valid Splunk Enterprise license, this Docker image can index up to 20Gb per day ...

cheers, MuS

Get Updates on the Splunk Community!

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...