splunk / splunk/docker-splunk

Please include eu-stack utility into the docker image to allow performance troubleshooting within an indexer cluster

Open
#653 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
549
Forks
277
Avg merge
3d 9h
Merged PRs (30d)
2

Description

I'm using the Splunk Operator for K8s, https://github.com/splunk/splunk-operator

Using the operator we have multiple indexer clusters deployed, I recently had an issue where indexers became unresponsive and I restarted them.

Ideally I'd like to see the collect_stacks.sh script provided by splunk support inside the Splunk enterprise docker image. However at minimum could we have eu-stack?

This way when a performance issue occurs, I can collect eu-stack's from splunkd inside the container to send to Splunk support for further analysis?

Thanks

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing how the Splunk Enterprise Docker image is assembled and how the eu-stack utility or collect_stacks.sh script is obtained. Confirm the utility is present and usable inside the resulting image for collecting splunkd stacks during indexer performance troubleshooting.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.