Getting Data In

Using custom indices to retrieve docker container logs

nanduni
Explorer

Hi all,

I want to retrieve the event logs of a docker container with a custom index that I created using the Splunk web interface.

Details about the custom index
Name: abc
App: app-docker
Home Path: $SPLUNK_DB/abc/db

When I use this index to get container logs, I cannot find the container running in Docker Overview dashboard (Logs by Container - Splunk Logging Driver, https://docs.docker.com/engine/admin/logging/splunk/). I can only find containers which uses main index.

How can I retrieve container logs that use tokens referencing to this custom index?

Thank you.

Tags (1)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Have you tried to search this: index=abc earliest=0 ?

View solution in original post

0 Karma

MuS
SplunkTrust
SplunkTrust

Have you tried to search this: index=abc earliest=0 ?

0 Karma

nanduni
Explorer

Thank you very much.

You are right, I am getting the event outputs for index=abc earliest=0. So why do you think that container not appears in the Docker Overview dashboard.

0 Karma

MuS
SplunkTrust
SplunkTrust

change the indexes that are searched by default for your role. Most likely the dashboard searches are created without a specific index name. See the docs for more details to change the by default searched indexes http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/Aboutusersandroles

I will convert this to an answer, feel free to accept it

Hope this helps ...

cheers, MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...