Unable to add splunk universal forwarder as a sidecar
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 549
- Forks
- 277
- Avg merge
- 3d 9h
- Merged PRs (30d)
- 2
Description
Getting below error when I'm trying to set up a splunk side car container.
ERROR OBSERVED
TASK [splunk_universal_forwarder : Setup global HEC] ***************************
task path: /opt/ansible/roles/splunk_common/tasks/set_as_hec_receiver.yml:4
fatal: [localhost]: FAILED! => {
"cache_control": "private",
"changed": false,
"connection": "Close",
"content_length": "130",
"content_type": "text/xml; charset=UTF-8",
"date": "Tue, 07 Dec 2021 09:34:20 GMT",
"elapsed": 0,
"redirected": false,
"server": "Splunkd",
"status": 401,
"url": "https://127.0.0.1:8089/services/data/inputs/http/http",
"vary": "Cookie, Authorization",
"www_authenticate": "Basic realm=\"/splunk\"",
"x_content_type_options": "nosniff",
"x_frame_options": "SAMEORIGIN"
}
MSG:
Status code was 401 and not [200]: HTTP Error 401: Unauthorized
How I'm adding universal forwarder to my deployment in K8s
- name: splunk-forwarder
image: splunk/universalforwarder:8.2
env:
- name: SPLUNK_START_ARGS
value: "--accept-license"
- name: ANSIBLE_EXTRA_FLAGS
value: "-vv"
- name: SPLUNK_CMD
value: 'install app /tmp/splunk-creds/splunkclouduf.spl, add monitor /app/logs'
- name: SPLUNK_PASSWORD
valueFrom:
secretKeyRef:
name: mia-env-secret
key: SPLUNK_UF_PASSWORD
resources: {}
volumeMounts:
- name: splunk-uf-creds-spl
mountPath: tmp/splunk-creds
- name: logs
mountPath: /app/logs
There aren't many examples of how to use docker universalforwarder out there, any help or reference to how to containerized version of UF is appreciated.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with /opt/ansible/roles/splunk_common/tasks/set_as_hec_receiver.yml:4 and the splunk/universalforwarder:8.2 container configuration shown in the manifest. Reproduce the deployment and inspect the 401 response, credentials, environment variables, and volume mounts; done means the sidecar starts and the HEC setup task succeeds.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, kubernetes
- Domain
- devops, infrastructure
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100