Is Kubernetes a supported deployment model for Splunk instead of deploying on virtual machines or bare metal?
Folks,
Some useful information about using the community supported Splunk Enterprise docker image is available at :
https://github.com/splunk/docker-splunk/tree/master/enterprise#How-to-use-the-Splunk-Enterprise-Dock...
https://conf.splunk.com/files/2016/slides/how-to-run-splunk-as-a-docker-image.pdf
https://conf.splunk.com/files/2017/slides/monitoring-docker-containers-with-splunk.pdf
https://www.evernote.com/shard/s306/sh/1416f078-9a5d-41ba-9d99-f2f4377cb857/2d92e5d3f6d9310b
https://www.splunk.com/blog/2018/01/17/hands-on-lab-sandboxing-with-splunk-with-docker.html
https://www.splunk.com/blog/2015/08/24/collecting-docker-logs-and-stats-with-splunk.html
https://www.tekstream.com/news/containerization-and-splunk-how-docker-and-splunk-work-together/
UPDATE FROM FUTURE. The year is 2020. Kubernetes has taken over the world. Here is Splunk's alpha operator.
https://github.com/splunk/splunk-operator
UPDATE: While official Kubernetes support is still to come, we have released a supported docker image and have shared some early POC deployments that explore key concepts in Kubernetes here: https://github.com/splunk/docker-splunk/tree/master/test_scenarios/kubernetes
hi mwelch,
As of today, Splunk does not officially support running in containers or deploying the entire architecture on container orchestrators like k8s.
We are working internally to iron out the details of what we can support in the near future and beyond, as containerization and platforms like docker, kubernetes and openshift make their way into prod environments and as we ourselves look at what container orchestration can do for us.
This obviously does not mean it cannot be done, there are customers who have forged ahead in working through those learnings, and have had success, and we have kept a close eye on the results.
There is much to iron out to deal with the stateful nature of parts of the Splunk Architecture, as well as determining what the tradeoff and impacts are.
I would expect, eventually, to see something akin to our support of Splunk on virtualized platforms, with something like, running the UF as a deamonset as probably the most realistic option to arrive in the near term, but I am speculating.
If there is any change in that, I'll be sure to update this post. Also come join us in #kubernetes on the Splunk Community Slack channel. ( splk.it/slack )
Thank you. I have requested access to the slack channel and look forward to discussing further.
here is a quick getting started doc on it:
https://www.evernote.com/shard/s306/sh/1416f078-9a5d-41ba-9d99-f2f4377cb857/2d92e5d3f6d9310b
@mmodestino_splunk could probably give more insight.