Getting Data In

Using splunk deployment server to detect virtual containers

tevgey23
Explorer

Can Splunk deployment server detect a container ID in a virtual environment, which was created... say by openvz, and apply the inputs.conf file to that container? This is necessary since the containers keep changing.

Tags (1)
0 Karma

Damien_Dallimor
Ultra Champion

I would say no.

serverclass.conf has whitelist,machineType(deprecated) and machineTypesFilter properties to detect deployment clients.

Perhaps you could set your virtual container's IP addresses to encode the container ID, as described here , and then you can use the whitelist property to setup your serverclass stanzas based on the IP addresses.

0 Karma

tevgey23
Explorer

Currently were using a script within puppet to identify those containers, does the deployment server support such a script. I guess what I can do is pupptize the host, install the forwarder,
and then if its a container Ill add the serverclass and deployment configuration files, from there
the Splunk server can populate the inputs.conf file. Does that sound like something that would work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...