Outcold Solutions is sponsoring Splunk .conf26 - see you there!

Monitoring Docker

Forward Docker container logs, metrics, and events to Splunk.

Run a single Collectord container per host and forward logs, metrics, and Docker events from every container on the box - automatically.

Install in 5 minutes Read concepts Troubleshooting

Installation

Set up Splunk app, HEC, and run collectord container
Installation

Concepts

What Collectord does, the data model, and how configuration layers
Concepts

Configuration

Config file layout and override settings
Configuration

Container annotations

Use container labels to control log forwarding behavior
Container annotations

Container labels reference

Full list of every container label grouped by datatype
Container labels reference

Splunk indexes

Configure which Splunk indexes receive data
Splunk indexes

Splunk field extraction

Define search-time field extraction rules for container logs
Splunk field extraction

Splunk HTTP Event Collector

Configure SSL and connection settings for Splunk HEC
Splunk HTTP Event Collector

Prometheus metrics

Scrape Prometheus metrics from containers
Prometheus metrics

Multiple clusters

Identify and differentiate multiple clusters in Splunk
Multiple clusters

Object polling

Poll Docker API for container and image data
Object polling

License server

Distribute license keys across hosts from a central URL
License server

Alerts

Predefined alerts for license, health, and container restarts
Alerts

Troubleshooting

Run verify command and diagnose common issues
Troubleshooting

Release history

Changelog of all collectord and Splunk app releases
Release history

Upgrade

Step-by-step version upgrade instructions
Upgrade

Security

Image security, container privileges, and Docker API access
Security