Outcold Solutions is sponsoring Splunk .conf26 - see you there!
Monitoring Docker
Forward Docker container logs, metrics, and events to Splunk.
Run a single Collectord container per host and forward logs, metrics, and Docker events from every container on the box - automatically.
Install in 5 minutes Read concepts Troubleshooting
Installation
Set up Splunk app, HEC, and run collectord container
→ Installation
Concepts
What Collectord does, the data model, and how configuration layers
→ Concepts
Configuration
Config file layout and override settings
→ Configuration
Container annotations
Use container labels to control log forwarding behavior
→ Container annotations
Container labels reference
Full list of every container label grouped by datatype
→ Container labels reference
Splunk indexes
Configure which Splunk indexes receive data
→ Splunk indexes
Splunk field extraction
Define search-time field extraction rules for container logs
→ Splunk field extraction
Splunk HTTP Event Collector
Configure SSL and connection settings for Splunk HEC
→ Splunk HTTP Event Collector
Prometheus metrics
Scrape Prometheus metrics from containers
→ Prometheus metrics
Multiple clusters
Identify and differentiate multiple clusters in Splunk
→ Multiple clusters
Object polling
Poll Docker API for container and image data
→ Object polling
License server
Distribute license keys across hosts from a central URL
→ License server
Alerts
Predefined alerts for license, health, and container restarts
→ Alerts
Troubleshooting
Run verify command and diagnose common issues
→ Troubleshooting
Release history
Changelog of all collectord and Splunk app releases
→ Release history
Upgrade
Step-by-step version upgrade instructions
→ Upgrade
Security
Image security, container privileges, and Docker API access
→ Security