Getting Data In

Where does docker's splunk-logging-plugin read splunk-capath from?

positr0n
New Member

I have docker running with docker-machine on my Mac.

In my docker VM I have loaded my company's internal root certificate in /etc/ssl/cacert.pem.

Install the plugin with docker plugin enable splunk-logging-plugin

In /etc/docker/daemon.json I set splunk-capath to that file.

When I start a docker image I get error creating splunk logger: open /etc/ssl/cacert.pem: no such file or directory"

When I change splunk-capath to a random cert on the image I'm running it appears to load and try to use it for TLS verification.

Does this mean I need to add the corporate certs to every docker image I am going to run for the docker splunk forwarder to work?

0 Karma

positr0n
New Member

Answering my question, the splunk logger runs in it's own docker container. https://github.com/splunk/docker-logging-plugin/blob/develop/Dockerfile

So splunk-capath is in this container. I guess you need to make your own image FROM that one with your certs if you want to add certs to it.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...