Getting Data In

Universal Forwarder not communicating to server

ghostlab
Loves-to-Learn Lots

I have an Alpine image with splunk forwarder installed in it. I am trying to monitor one log file from with in the container and log it to the splunk server.

Step 1: Base image with Alpine and unzipped splunkforwarder.tgz file

Step 2: Using this base image to dockerize my node application.

               RUN ../../../opt/splunk/bin/splunk start --accept-license --answer-yes --seed-passwd password

               RUN ../../../opt/splunk/bin/splunk add forward-server server-ip:9997 -auth admin:username

               RUN ../../../opt/splunk/bin/splunk add monitor ./logs -sourcetype logs

               RUN ../../../opt/splunk/bin/splunk restart

               RUN ../../../opt/splunk/bin/splunk enable boot-start #dont know if its needed

I am still not receiving any logs in the splunk server. Is there anything I need to do for the spluk forwarder to communicate with splunk-server from with in the container.

Thank you.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...