Getting Data In

Using custom indices to retrieve docker container logs

nanduni
Explorer

Hi all,

I want to retrieve the event logs of a docker container with a custom index that I created using the Splunk web interface.

Details about the custom index
Name: abc
App: app-docker
Home Path: $SPLUNK_DB/abc/db

When I use this index to get container logs, I cannot find the container running in Docker Overview dashboard (Logs by Container - Splunk Logging Driver, https://docs.docker.com/engine/admin/logging/splunk/). I can only find containers which uses main index.

How can I retrieve container logs that use tokens referencing to this custom index?

Thank you.

Tags (1)
0 Karma
1 Solution

MuS
Legend

Have you tried to search this: index=abc earliest=0 ?

View solution in original post

0 Karma

MuS
Legend

Have you tried to search this: index=abc earliest=0 ?

0 Karma

nanduni
Explorer

Thank you very much.

You are right, I am getting the event outputs for index=abc earliest=0. So why do you think that container not appears in the Docker Overview dashboard.

0 Karma

MuS
Legend

change the indexes that are searched by default for your role. Most likely the dashboard searches are created without a specific index name. See the docs for more details to change the by default searched indexes http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Aboutusersandroles

I will convert this to an answer, feel free to accept it

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...