Outcold Solutions is sponsoring Splunk .conf26 - see you there!

# Monitoring Docker

## Forward Docker container logs, metrics, and events to Splunk.

Run a single Collectord container per host and forward logs, metrics, and Docker events from every container on the box - automatically.

[Install in 5 minutes](/content/docs/monitoring-docker/installation/index.html) [Read concepts](/content/docs/monitoring-docker/concepts/index.html) [Troubleshooting](/content/docs/monitoring-docker/troubleshooting/index.html)

### Installation  
Set up Splunk app, HEC, and run collectord container  
→ [Installation](/content/docs/monitoring-docker/installation/index.html)

### Concepts  
What Collectord does, the data model, and how configuration layers  
→ [Concepts](/content/docs/monitoring-docker/concepts/index.html)

### Configuration  
Config file layout and override settings  
→ [Configuration](/content/docs/monitoring-docker/configuration/index.html)

### Container annotations  
Use container labels to control log forwarding behavior  
→ [Container annotations](/content/docs/monitoring-docker/annotations/index.html)

### Container labels reference  
Full list of every container label grouped by datatype  
→ [Container labels reference](/content/docs/monitoring-docker/annotations-reference/index.html)

### Splunk indexes  
Configure which Splunk indexes receive data  
→ [Splunk indexes](/content/docs/monitoring-docker/splunk-indexes/index.html)

### Splunk field extraction  
Define search-time field extraction rules for container logs  
→ [Splunk field extraction](/content/docs/monitoring-docker/splunk-fields-extraction/index.html)

### Splunk HTTP Event Collector  
Configure SSL and connection settings for Splunk HEC  
→ [Splunk HTTP Event Collector](/content/docs/monitoring-docker/splunk-output/index.html)

### Prometheus metrics  
Scrape Prometheus metrics from containers  
→ [Prometheus metrics](/content/docs/monitoring-docker/prometheus/index.html)

### Multiple clusters  
Identify and differentiate multiple clusters in Splunk  
→ [Multiple clusters](/content/docs/monitoring-docker/clusters/index.html)

### Object polling  
Poll Docker API for container and image data  
→ [Object polling](/content/docs/monitoring-docker/objects/index.html)

### License server  
Distribute license keys across hosts from a central URL  
→ [License server](/content/docs/monitoring-docker/license-server/index.html)

### Alerts  
Predefined alerts for license, health, and container restarts  
→ [Alerts](/content/docs/monitoring-docker/alerts/index.html)

### Troubleshooting  
Run verify command and diagnose common issues  
→ [Troubleshooting](/content/docs/monitoring-docker/troubleshooting/index.html)

### Release history  
Changelog of all collectord and Splunk app releases  
→ [Release history](/content/docs/monitoring-docker/release-history/index.html)

### Upgrade  
Step-by-step version upgrade instructions  
→ [Upgrade](/content/docs/monitoring-docker/upgrade/index.html)

### Security  
Image security, container privileges, and Docker API access  
→ [Security](/content/docs/monitoring-docker/security/index.html)
