Splunk Search

Splunk Daemonset for kubernetes not indexing data due to read only filesystem

vidhijain333
Loves-to-Learn

I have configured splunk daemonset for k8s cluster. Agent logs are flowing. However the application logs are not getting indexed, as /var/lib/docker/containers is owned by root and a read only file system.
Also I am not able to change permissions of /var/lib/docker/containers. PS - We are running splunk agent with a non-root user.

Any help ?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...