Knowledge Management

splunk-docker-logging-plugin sending logs to Splunk Enterprise but not storing the logs in Docker host machine

charanbr
New Member

Hi Team,

In general, when we create a Docker container, the logs of that container will be stored in the host machine path /DOCKER_PATH/docker-data/container/CONTAINER_ID/CONTAINER_ID.json. Now, we are using splunk-docker-logging-plugin, after implementing splunk-docker-logging-plugin, the logs file /DOCKER_PATH/docker-data/container/CONTAINER_ID/CONTAINER_ID.json itself is not getting created. The logs are directly pushed to Splunk server but the logs are not getting stored in the container log file(/DOCKER_PATH/docker-data/container/CONTAINER_ID/CONTAINER_ID.json) in the Docker host machine. So can you please confirm whether we can store logs in both the places - 1) Forwarding to Splunk server and 2) Storing the logs in /DOCKER_PATH/docker-data/container/CONTAINER_ID/CONTAINER_ID.json till the container is alive. 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...