Knowledge Management

Is Splunk supported on Kubernetes

mwelch
Engager

Is Kubernetes a supported deployment model for Splunk instead of deploying on virtual machines or bare metal?

Tags (1)

mattymo
Splunk Employee
Splunk Employee

Getting closer 🙂

https://github.com/splunk/splunk-operator

- MattyMo

mattymo
Splunk Employee
Splunk Employee

UPDATE FROM FUTURE. The year is 2020. Kubernetes has taken over the world. Here is Splunk's alpha operator.

https://github.com/splunk/splunk-operator

UPDATE: While official Kubernetes support is still to come, we have released a supported docker image and have shared some early POC deployments that explore key concepts in Kubernetes here: https://github.com/splunk/docker-splunk/tree/master/test_scenarios/kubernetes

hi mwelch,

As of today, Splunk does not officially support running in containers or deploying the entire architecture on container orchestrators like k8s.

We are working internally to iron out the details of what we can support in the near future and beyond, as containerization and platforms like docker, kubernetes and openshift make their way into prod environments and as we ourselves look at what container orchestration can do for us.

This obviously does not mean it cannot be done, there are customers who have forged ahead in working through those learnings, and have had success, and we have kept a close eye on the results.

There is much to iron out to deal with the stateful nature of parts of the Splunk Architecture, as well as determining what the tradeoff and impacts are.

I would expect, eventually, to see something akin to our support of Splunk on virtualized platforms, with something like, running the UF as a deamonset as probably the most realistic option to arrive in the near term, but I am speculating.

If there is any change in that, I'll be sure to update this post. Also come join us in #kubernetes on the Splunk Community Slack channel. ( splk.it/slack )

- MattyMo

mwelch
Engager

Thank you. I have requested access to the slack channel and look forward to discussing further.

0 Karma

cmerriman
Super Champion

here is a quick getting started doc on it:
https://www.evernote.com/shard/s306/sh/1416f078-9a5d-41ba-9d99-f2f4377cb857/2d92e5d3f6d9310b

@mmodestino_splunk could probably give more insight.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...