Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช

Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช

Splunk ื”ื•ื ืื—ื“ ืžื›ืžื” ืžืžื•ืฆืจื™ ืื™ืกื•ืฃ ื•ื ื™ืชื•ื— ื™ื•ืžื ื™ื ืžืกื—ืจื™ื™ื ื”ืžื•ื›ืจื™ื ื‘ื™ื•ืชืจ. ื’ื ืขื›ืฉื™ื•, ื›ืฉื”ืžื›ื™ืจื•ืช ื›ื‘ืจ ืœื ืžืชื‘ืฆืขื•ืช ื‘ืจื•ืกื™ื”, ื–ื• ืœื ืกื™ื‘ื” ืœื ืœื›ืชื•ื‘ ื”ื•ืจืื•ืช/ื›ื™ืฆื“ ืœืขืฉื•ืช ืœืžื•ืฆืจ ื–ื”.

ืžืฉื™ืžื”: ืื™ืกื•ืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช ืžืฆืžืชื™ ื“ื•ืงืจ ื‘-Splunk ืžื‘ืœื™ ืœืฉื ื•ืช ืืช ืชืฆื•ืจืช ื”ืžื—ืฉื‘ ื”ืžืืจื—

ืื ื™ ืจื•ืฆื” ืœื”ืชื—ื™ืœ ืขื ื”ื’ื™ืฉื” ื”ืจืฉืžื™ืช, ืฉื ืจืื™ืช ืงืฆืช ืžื•ื–ืจื” ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-Docker.
ืงื™ืฉื•ืจ ืœืจื›ื–ืช Docker
ืžื” ื™ืฉ ืœื ื•:

1. ืชืžื•ื ื” ืคื•ืœื™ื

$ docker pull splunk/universalforwarder:latest

2. ื”ืชื—ืœ ืืช ื”ืžื™ื›ืœ ืขื ื”ืคืจืžื˜ืจื™ื ื”ื“ืจื•ืฉื™ื

$ docker run -d  -p 9997:9997 -e 'SPLUNK_START_ARGS=--accept-license' -e 'SPLUNK_PASSWORD=<password>' splunk/universalforwarder:latest

3. ืื ื—ื ื• ื ื›ื ืกื™ื ืœืžื™ื›ืœ

docker exec -it <container-id> /bin/bash

ืœืื—ืจ ืžื›ืŸ, ืื ื• ืžืชื‘ืงืฉื™ื ืœืคื ื•ืช ืœื›ืชื•ื‘ืช ื™ื“ื•ืขื” ื‘ืชื™ืขื•ื“.

ื•ืชื’ื“ื™ืจ ืืช ื”ืžื›ื•ืœื” ืœืื—ืจ ื”ืคืขืœืชื•:


./splunk add forward-server <host name or ip address>:<listening port>
./splunk add monitor /var/log
./splunk restart

ืœึทื—ึฒื›ื•ึนืช. ืžื”?

ืื‘ืœ ื”ื”ืคืชืขื•ืช ืœื ื ื’ืžืจื•ืช ืฉื. ืื ืชืคืขื™ืœ ืืช ื”ืžื™ื›ืœ ืžื”ืชืžื•ื ื” ื”ืจืฉืžื™ืช ื‘ืžืฆื‘ ืื™ื ื˜ืจืืงื˜ื™ื‘ื™, ืชืจืื” ืืช ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื:

ืงืฆืช ืื›ื–ื‘ื”


$ docker run -it -p 9997:9997 -e 'SPLUNK_START_ARGS=--accept-license' -e 'SPLUNK_PASSWORD=password' splunk/universalforwarder:latest

PLAY [Run default Splunk provisioning] *******************************************************************************************************************************************************************************************************
Tuesday 09 April 2019  13:40:38 +0000 (0:00:00.096)       0:00:00.096 *********

TASK [Gathering Facts] ***********************************************************************************************************************************************************************************************************************
ok: [localhost]
Tuesday 09 April 2019  13:40:39 +0000 (0:00:01.520)       0:00:01.616 *********

TASK [Get actual hostname] *******************************************************************************************************************************************************************************************************************
changed: [localhost]
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.599)       0:00:02.215 *********
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.054)       0:00:02.270 *********

TASK [set_fact] ******************************************************************************************************************************************************************************************************************************
ok: [localhost]
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.075)       0:00:02.346 *********
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.067)       0:00:02.413 *********
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.060)       0:00:02.473 *********
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.051)       0:00:02.525 *********
Tuesday 09 April 2019  13:40:40 +0000 (0:00:00.056)       0:00:02.582 *********
Tuesday 09 April 2019  13:40:41 +0000 (0:00:00.216)       0:00:02.798 *********
included: /opt/ansible/roles/splunk_common/tasks/change_splunk_directory_owner.yml for localhost
Tuesday 09 April 2019  13:40:41 +0000 (0:00:00.087)       0:00:02.886 *********

TASK [splunk_common : Update Splunk directory owner] *****************************************************************************************************************************************************************************************
ok: [localhost]
Tuesday 09 April 2019  13:40:41 +0000 (0:00:00.324)       0:00:03.210 *********
included: /opt/ansible/roles/splunk_common/tasks/get_facts.yml for localhost
Tuesday 09 April 2019  13:40:41 +0000 (0:00:00.094)       0:00:03.305 *********

ะฝัƒ ะธ ั‚ะฐะบ ะดะฐะปะตะต...

ื’ื“ื•ืœ. ื”ืชืžื•ื ื” ืืคื™ืœื• ืœื ืžื›ื™ืœื” ื—ืคืฅ. ื›ืœื•ืžืจ, ื‘ื›ืœ ืคืขื ืฉืชืชื—ื™ืœ ื™ื™ืงื— ื–ืžืŸ ืœื”ื•ืจื™ื“ ืืช ื”ืืจื›ื™ื•ืŸ ืขื ืงื‘ืฆื™ื ื‘ื™ื ืืจื™ื™ื, ืœืคืจื•ืง ื•ืœื”ื’ื“ื™ืจ.
ืžื” ืขื docker-way ื•ื›ืœ ื–ื”?

ืœื ืชื•ื“ื”. ื ืœืš ื‘ื“ืจืš ืื—ืจืช. ืžื” ืื ื ื‘ืฆืข ืืช ื›ืœ ื”ืคืขื•ืœื•ืช ื”ืœืœื• ื‘ืฉืœื‘ ื”ื”ืจื›ื‘ื”? ืื– ื‘ื•ืื• ื ืœืš!

ื›ื“ื™ ืœื ืœื”ืชืขื›ื‘ ื™ื•ืชืจ ืžื“ื™, ืื ื™ ืืจืื” ืœื›ื ืืช ื”ืชืžื•ื ื” ื”ืกื•ืคื™ืช ืžื™ื“:

ื“ื•ืงืจืคื™ืœ

# ะขัƒั‚ ัƒ ะบะพะณะพ ะบะฐะบะธะต ะฟั€ะตะดะฟะพั‡ั‚ะตะฝะธั
FROM centos:7

# ะ—ะฐะดะฐั‘ะผ ะฟะตั€ะตะผะตะฝะฝั‹ะต, ั‡ั‚ะพะฑั‹ ะบะฐะถะดั‹ะน ั€ะฐะท ะฟั€ะธ ัั‚ะฐั€ั‚ะต ะฝะต ัƒะบะฐะทั‹ะฒะฐั‚ัŒ ะธั…
ENV SPLUNK_HOME /splunkforwarder
ENV SPLUNK_ROLE splunk_heavy_forwarder
ENV SPLUNK_PASSWORD changeme
ENV SPLUNK_START_ARGS --accept-license

# ะกั‚ะฐะฒะธะผ ะฟะฐะบะตั‚ั‹
# wget - ั‡ั‚ะพะฑั‹ ัะบะฐั‡ะฐั‚ัŒ ะฐั€ั‚ะตั„ะฐะบั‚ั‹
# expect - ะฟะพะฝะฐะดะพะฑะธั‚ัั ะดะปั ะฟะตั€ะฒะพะฝะฐั‡ะฐะปัŒะฝะพะณะพ ะทะฐะฟัƒัะบะฐ Splunk ะฝะฐ ัั‚ะฐะฟะต ัะฑะพั€ะบะธ
# jq - ะธัะฟะพะปัŒะทัƒะตั‚ัั ะฒ ัะบั€ะธะฟั‚ะฐั…, ะบะพั‚ะพั€ั‹ะต ัะพะฑะธั€ะฐัŽั‚ ัั‚ะฐั‚ะธัั‚ะธะบัƒ ะดะพะบะตั€ะฐ
RUN yum install -y epel-release 
    && yum install -y wget expect jq

# ะšะฐั‡ะฐะตะผ, ั€ะฐัะฟะฐะบะพะฒั‹ะฒะฐะตะผ, ัƒะดะฐะปัะตะผ
RUN wget -O splunkforwarder-7.2.4-8a94541dcfac-Linux-x86_64.tgz 'https://www.splunk.com/bin/splunk/DownloadActivityServlet?architecture=x86_64&platform=linux&version=7.2.4&product=universalforwarder&filename=splunkforwarder-7.2.4-8a94541dcfac-Linux-x86_64.tgz&wget=true' 
    && wget -O docker-18.09.3.tgz 'https://download.docker.com/linux/static/stable/x86_64/docker-18.09.3.tgz' 
    && tar -xvf splunkforwarder-7.2.4-8a94541dcfac-Linux-x86_64.tgz 
    && tar -xvf docker-18.09.3.tgz  
    && rm -f splunkforwarder-7.2.4-8a94541dcfac-Linux-x86_64.tgz 
    && rm -f docker-18.09.3.tgz

# ะก shell ัะบั€ะธะฟั‚ะฐะผะธ ะฒัั‘ ะฟะพะฝัั‚ะฝะพ, ะฐ ะฒะพั‚ inputs.conf, splunkclouduf.spl ะธ first_start.sh ะฝัƒะถะดะฐัŽั‚ัั ะฒ ะฟะพััะฝะตะฝะธะธ. ะžะฑ ัั‚ะพะผ ั€ะฐััะบะฐะถัƒ ะฟะพัะปะต source ั‚ัะณะฐ.
COPY [ "inputs.conf", "docker-stats/props.conf", "/splunkforwarder/etc/system/local/" ]
COPY [ "docker-stats/docker_events.sh", "docker-stats/docker_inspect.sh", "docker-stats/docker_stats.sh", "docker-stats/docker_top.sh", "/splunkforwarder/bin/scripts/" ]
COPY splunkclouduf.spl /splunkclouduf.spl
COPY first_start.sh /splunkforwarder/bin/

#  ะ”ะฐั‘ะผ ะฟั€ะฐะฒะฐ ะฝะฐ ะธัะฟะพะปะฝะตะฝะธะต, ะดะพะฑะฐะฒะปัะตะผ ะฟะพะปัŒะทะพะฒะฐั‚ะตะปั ะธ ะฒั‹ะฟะพะปะฝัะตะผ ะฟะตั€ะฒะพะฝะฐั‡ะฐะปัŒะฝัƒัŽ ะฝะฐัั‚ั€ะพะนะบัƒ
RUN chmod +x /splunkforwarder/bin/scripts/*.sh 
    && groupadd -r splunk 
    && useradd -r -m -g splunk splunk 
    && echo "%sudo ALL=NOPASSWD:ALL" >> /etc/sudoers 
    && chown -R splunk:splunk $SPLUNK_HOME 
    && /splunkforwarder/bin/first_start.sh 
    && /splunkforwarder/bin/splunk install app /splunkclouduf.spl -auth admin:changeme 
    && /splunkforwarder/bin/splunk restart

# ะšะพะฟะธั€ัƒะตะผ ะธะฝะธั‚ ัะบั€ะธะฟั‚ั‹
COPY [ "init/entrypoint.sh", "init/checkstate.sh", "/sbin/" ]

# ะŸะพ ะถะตะปะฐะฝะธัŽ. ะšะพะผัƒ ะฝัƒะถะฝะพ ะปะพะบะฐะปัŒะฝะพ ะธะผะตั‚ัŒ ะบะพะฝั„ะธะณะธ/ะปะพะณะธ, ะบะพะผัƒ ะฝะตั‚.
VOLUME [ "/splunkforwarder/etc", "/splunkforwarder/var" ]

HEALTHCHECK --interval=30s --timeout=30s --start-period=3m --retries=5 CMD /sbin/checkstate.sh || exit 1

ENTRYPOINT [ "/sbin/entrypoint.sh" ]
CMD [ "start-service" ]

ืื– ืžื” ื›ืœื•ืœ ื‘

first_start.sh

#!/usr/bin/expect -f
set timeout -1
spawn /splunkforwarder/bin/splunk start --accept-license
expect "Please enter an administrator username: "
send -- "adminr"
expect "Please enter a new password: "
send -- "changemer"
expect "Please confirm new password: "
send -- "changemer"
expect eof

ื‘ื”ืชื—ืœื” ื”ืจืืฉื•ื ื”, Splunk ืžื‘ืงืฉ ืžืžืš ืœืชืช ืœื• ื›ื ื™ืกื”/ืกื™ืกืžื”, ืื‘ืœ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื ืชื•ื ื™ื ื”ืืœื” ืจืง ื›ื“ื™ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ื ื™ื”ื•ืœ ืขื‘ื•ืจ ืื•ืชื” ื”ืชืงื ื” ืžืกื•ื™ืžืช, ื›ืœื•ืžืจ ื‘ืชื•ืš ื”ืงื•ื ื˜ื™ื™ื ืจ. ื‘ืžืงืจื” ืฉืœื ื•, ืื ื—ื ื• ืจืง ืจื•ืฆื™ื ืœื”ืคืขื™ืœ ืืช ื”ืžื›ื•ืœื” ื›ื“ื™ ืฉื”ื›ืœ ื™ืขื‘ื•ื“ ื•ื”ื‘ื•ืœื™ื ื™ื–ืจื•ื ื›ืžื• ื ื”ืจ. ื›ืžื•ื‘ืŸ, ื–ื” ืงืฉื™ื—, ืื‘ืœ ืœื ืžืฆืืชื™ ื“ืจื›ื™ื ืื—ืจื•ืช.

ื‘ื”ืžืฉืš ืœืคื™ ื”ืชืกืจื™ื˜ ืžื‘ื•ืฆืข

/splunkforwarder/bin/splunk install app /splunkclouduf.spl -auth admin:changeme

splunkclouduf.spl โ€” ื–ื”ื• ืงื•ื‘ืฅ ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ Splunk Universal Forwarder, ืื•ืชื• ื ื™ืชืŸ ืœื”ื•ืจื™ื“ ืžืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜.

ื”ื™ื›ืŸ ืœืœื—ื•ืฅ ืœื”ื•ืจื“ื” (ื‘ืชืžื•ื ื•ืช)Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช

Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช
ื–ื”ื• ืืจื›ื™ื•ืŸ ืจื’ื™ืœ ืฉื ื™ืชืŸ ืœืคืจื•ืง. ื‘ืคื ื™ื ื™ืฉ ืื™ืฉื•ืจื™ื ื•ืกื™ืกืžื” ืœื—ื™ื‘ื•ืจ ืœ-SplunkCloud ืฉืœื ื• ื• outputs.conf ืขื ืจืฉื™ืžื” ืฉืœ ืžื•ืคืขื™ ื”ืงืœื˜ ืฉืœื ื•. ืงื•ื‘ืฅ ื–ื” ื™ื”ื™ื” ืจืœื•ื•ื ื˜ื™ ืขื“ ืฉืชืชืงื™ืŸ ืžื—ื“ืฉ ืืช ื”ืชืงื ืช Splunk ืฉืœืš ืื• ืชื•ืกื™ืฃ ืฆื•ืžืช ืงืœื˜ ืื ื”ื”ืชืงื ื” ื”ื™ื ืžืงื•ืžื™ืช. ืœื›ืŸ, ืื™ืŸ ืฉื•ื ืคืกื•ืœ ื‘ื”ื•ืกืคืชื• ื‘ืชื•ืš ื”ืžื™ื›ืœ.

ื•ื”ื“ื‘ืจ ื”ืื—ืจื•ืŸ ื”ื•ื ื”ืคืขืœื” ืžื—ื“ืฉ. ื›ืŸ, ื›ื“ื™ ืœื”ื—ื™ืœ ืืช ื”ืฉื™ื ื•ื™ื™ื, ืขืœื™ืš ืœื”ืคืขื™ืœ ืื•ืชื• ืžื—ื“ืฉ.

ื‘ืฉืœื ื• inputs.conf ืื ื• ืžื•ืกื™ืคื™ื ืืช ื”ื™ื•ืžื ื™ื ืฉื‘ืจืฆื•ื ื ื• ืœืฉืœื•ื— ืœ-Splunk. ืื™ืŸ ืฆื•ืจืš ืœื”ื•ืกื™ืฃ ืืช ื”ืงื•ื‘ืฅ ื”ื–ื” ืœืชืžื•ื ื” ืื, ืœืžืฉืœ, ืืชื” ืžืคื™ืฅ ื”ื’ื“ืจื•ืช ื‘ืืžืฆืขื•ืช ื‘ื•ื‘ื”. ื”ื“ื‘ืจ ื”ื™ื—ื™ื“ ื”ื•ื ืฉื”-Forwarder ืจื•ืื” ืืช ื”ื”ื’ื“ืจื•ืช ื›ืืฉืจ ื”ื“ืžื•ืŸ ืžืชื—ื™ืœ, ืื—ืจืช ื”ื•ื ื™ืฆื˜ืจืš ./splunk ื”ืคืขืœื” ืžื—ื“ืฉ.

ืื™ื–ื” ืกื•ื’ ืฉืœ ืกืงืจื™ืคื˜ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ืฉืœ docker ื”ื? ื™ืฉ ืคืชืจื•ืŸ ื™ืฉืŸ ื‘- Github ืž ื ืจื“ืฃ, ื”ืชืกืจื™ื˜ื™ื ื ืœืงื—ื• ืžืฉื ื•ืฉื•ื ื• ื›ืš ืฉื™ืขื‘ื“ื• ืขื ื’ืจืกืื•ืช ืขื“ื›ื ื™ื•ืช ืฉืœ Docker (ce-17.*) ื•-Splunk (7.*).

ืขื ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื•, ืืชื” ื™ื›ื•ืœ ืœื‘ื ื•ืช ืืช ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื

ืœื•ื—ื•ืช ืžื—ื•ื•ื ื™ื: (ื›ืžื” ืชืžื•ื ื•ืช)Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช

Splunk Universal Forwarder ื‘-Docker ื›ืื•ืกืฃ ื™ื•ืžื ื™ ืžืขืจื›ืช
ืงื•ื“ ื”ืžืงื•ืจ ืœืžืงืคื™ื ื ืžืฆื ื‘ืงื™ืฉื•ืจ ื”ืžื•ืคื™ืข ื‘ืกื•ืฃ ื”ืžืืžืจ. ืฉื™ื ืœื‘ ืฉื™ืฉ 2 ืฉื“ื•ืช ื ื‘ื—ืจื™ื: 1 - ื‘ื—ื™ืจืช ืื™ื ื“ืงืก (ื—ื™ืคื•ืฉ ืœืคื™ ืžืกื™ื›ื”), ื‘ื—ื™ืจืช ืžืืจื—/ืžื™ื›ืœ. ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉืชืฆื˜ืจืš ืœืขื“ื›ืŸ ืืช ืžืกื›ืช ื”ืื™ื ื“ืงืก, ื‘ื”ืชืื ืœืฉืžื•ืช ืฉื‘ื”ื ืืชื” ืžืฉืชืžืฉ.

ืœืกื™ื›ื•ื, ื‘ืจืฆื•ื ื™ ืœื”ืกื‘ ืืช ืชืฉื•ืžืช ืœื‘ื›ื ืœืคื•ื ืงืฆื™ื” ื”ึทืชื—ึธืœึธื”() ะฒ

entrypoint.sh

start() {
    trap teardown EXIT
	if [ -z $SPLUNK_INDEX ]; then
	echo "'SPLUNK_INDEX' env variable is empty or not defined. Should be 'dev' or 'prd'." >&2
	exit 1
	else
	sed -e "s/@index@/$SPLUNK_INDEX/" -i ${SPLUNK_HOME}/etc/system/local/inputs.conf
	fi
	sed -e "s/@hostname@/$(cat /etc/hostname)/" -i ${SPLUNK_HOME}/etc/system/local/inputs.conf
    sh -c "echo 'starting' > /tmp/splunk-container.state"
	${SPLUNK_HOME}/bin/splunk start
    watch_for_failure
}

ื‘ืžืงืจื” ืฉืœื™, ืขื‘ื•ืจ ื›ืœ ืกื‘ื™ื‘ื” ื•ื›ืœ ื™ืฉื•ืช ื‘ื•ื“ื“ืช, ื‘ื™ืŸ ืื ื–ื• ืืคืœื™ืงืฆื™ื” ื‘ืงื•ื ื˜ื™ื™ื ืจ ืื• ืžื›ื•ื ื” ืžืืจื—, ืื ื• ืžืฉืชืžืฉื™ื ื‘ืื™ื ื“ืงืก ื ืคืจื“. ื›ืš, ืžื”ื™ืจื•ืช ื”ื—ื™ืคื•ืฉ ืœื ืชืคื’ืข ื›ืืฉืจ ืชื”ื™ื” ื”ืฆื˜ื‘ืจื•ืช ืžืฉืžืขื•ืชื™ืช ืฉืœ ื ืชื•ื ื™ื. ื›ืœืœ ืคืฉื•ื˜ ืžืฉืžืฉ ืœืฉืžื•ืช ืื™ื ื“ืงืกื™ื: _. ืœื›ืŸ, ืขืœ ืžื ืช ืฉื”ืžื™ื›ืœ ื™ื”ื™ื” ืื•ื ื™ื‘ืจืกืœื™, ืœืคื ื™ ื”ืฉืงืช ื”ื“ืžื•ืŸ ืขืฆืžื•, ืื ื• ืžื—ืœื™ืคื™ื ืฆืžืื”ืชื• ื”ื›ืœืœื™ ืฉืœ ืฉื ื”ืกื‘ื™ื‘ื”. ืžืฉืชื ื” ืฉื ื”ืกื‘ื™ื‘ื” ืžื•ืขื‘ืจ ื“ืจืš ืžืฉืชื ื™ ืกื‘ื™ื‘ื”. ื ืฉืžืข ืžืฆื—ื™ืง.

ืจืื•ื™ ื’ื ืœืฆื™ื™ืŸ ืฉืžืกื™ื‘ื” ื›ืœืฉื”ื™ Splunk ืื™ื ื• ืžื•ืฉืคืข ืžื ื•ื›ื—ื•ืช ืคืจืžื˜ืจ ื”-docker ื”ืžืืจื—. ื”ื•ื ืขื“ื™ื™ืŸ ื™ืฉืœื— ื‘ืขืงืฉื ื•ืช ื™ื•ืžื ื™ื ืขื ื”ืžื–ื”ื” ืฉืœ ื”ืžื›ื•ืœื” ืฉืœื• ื‘ืฉื“ื” ื”ืžืืจื—. ื›ืคืชืจื•ืŸ, ืืชื” ื™ื›ื•ืœ ืœืขืœื•ืช / etc / hostname ืžื”ืžื—ืฉื‘ ื”ืžืืจื— ื•ื‘ืืชื—ื•ืœ ืœื‘ืฆืข ื”ื—ืœืคื•ืช ื“ื•ืžื•ืช ืœืฉืžื•ืช ื”ืื™ื ื“ืงืกื™ื.

ื“ื•ื’ืžื” docker-compose.yml

version: '2'
services:
  splunk-forwarder:
    image: "${IMAGE_REPO}/docker-stats-splunk-forwarder:${IMAGE_VERSION}"
    environment:
      SPLUNK_INDEX: ${ENVIRONMENT}
    volumes:
    - /etc/hostname:/etc/hostname:ro
    - /var/log:/var/log
    - /var/run/docker.sock:/var/run/docker.sock:ro

ืกืš ื”ื›ืœ

ื›ืŸ, ืื•ืœื™ ื”ืคืชืจื•ืŸ ืื™ื ื• ืื™ื“ื™ืืœื™ ื•ื‘ื•ื•ื“ืื™ ืœื ืื•ื ื™ื‘ืจืกืœื™ ืขื‘ื•ืจ ื›ื•ืœื, ืฉื›ืŸ ื™ืฉ ื”ืจื‘ื” "ืงื•ื“ ืงืฉื”". ืื‘ืœ ื‘ื”ืชื‘ืกืก ืขืœ ื–ื”, ื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœื‘ื ื•ืช ืชืžื•ื ื” ืžืฉืœื• ื•ืœืฉื™ื ืื•ืชื” ื‘ืืจื˜ื™ืคืงื˜ื•ืจื” ื”ืคืจื˜ื™ืช ืฉืœื•, ืื, ื›ืคื™ ืฉื–ื” ืงื•ืจื”, ืืชื” ืฆืจื™ืš Splunk Forwarder ื‘-Docker.

ืงื™ืฉื•ืจื™ื:

ืคืชืจื•ืŸ ืžื”ืžืืžืจ
ืคืชืจื•ืŸ ืฉืœ outcoldman ืฉื ืชืŸ ืœื ื• ื”ืฉืจืื” ืœืขืฉื•ืช ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ื—ืœืง ืžื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช
ืฉืึถืœ. ืชื™ืขื•ื“ ืœื”ื’ื“ืจืช Universal Forwarder

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”