Monitoring Docker Containers With Splunk PDF
Monitoring Docker Containers With Splunk PDF
with Splunk
The forward-looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or accurate
information. We do not assume any obligation to update any forward looking statements we may make. In
addition, any information about our roadmap outlines our general product direction and is subject to change
at any time without notice. It is for informational purposes only and shall not be incorporated into any contract
or other commitment. Splunk undertakes no obligation either to develop the features or functionality
described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in
the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2017 Splunk Inc. All rights reserved.
Who I am
Marc Chéné
• Product Manager, Engineer, APMer
• Dad/ super fan/ coach to 3, loves skiing, golfing,
music and a good drink
@marcchene
https://www.linkedin.com/in/marcchene
slack id: mchene
Forward-Looking Statements
During the course of this presentation, we may make forward-looking statements regarding future events or
the expected performance of the company. We caution you that such statements reflect our current
expectations and estimates based on factors currently known to us and that actual events or results could
differ materially. For important factors that may cause actual results to differ from those contained in our
forward-looking statements, please review our filings with the SEC.
The forward-looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or accurate
information. We do not assume any obligation to update any forward looking statements we may make. In
addition, any information about our roadmap outlines our general product direction and is subject to change
at any time without notice. It is for informational purposes only and shall not be incorporated into any contract
or other commitment. Splunk undertakes no obligation either to develop the features or functionality
described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in
the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2017 Splunk Inc. All rights reserved.
Agenda
▶ Monitoring Options
▶ Analytical Insight – Tips & Tricks
▶ The World of Metrics
▶ (coming soon!) Docker Moby - v2 logging Plugin
Monitoring Options
logs, events and perf stats
Splunk and Docker – At A Glance
Visibility in your
Monitoring for your Delivering Splunk as
Container
Cloud Environments Containers
Environments
Splunk Logging Driver for Deep Visibility in Amazon Make getting Splunk as easy
Docker Web Services (AWS) and in as a single Docker pull
• Built into Docker – no EC2 Container Services command from the Docker
extra software required (ECS) Hub/Store
• Insight into container and
apps running in containers Splunk provides support for Forwarders and Splunk
Google Cloud Platform (GCP) Enterprise pre-configured to
Docker Universal Control collect machine data from
Plane Container Host and Docker
• Insight into administration, API
changes, and composition
Splunk Collection Options for Docker
• Docker Native Logging – Splunk logging driver, Syslog, JSON, AWS CloudWatch, etc.
ABC.XYZ
19
Key Features
SPL
▶ Based on splunkd
▶ Dedicated Indexes for Metrics and Logs
23
GDI - Metric Ingestion Protocol: Collectd – Write
HTTP plugin
▶ Collectd, https://collectd.org - ~100 frontend plugins
▶ Scheduled push interval: 30secs
▶ # of metrics collected: ~350 (~1M measurements per day per server)
▶ Enabled plugins configurations, collectd.conf
Cloud
HTTPS - HEC
Splunk CollectD Package
write_http
plugin
Server Farm
Splunk Indexing Tier
cAdvisor
27
DEMO Docker
Metrics!
Docker Moby - V2
Logging Plugin
Section subtitle goes here
Docker Moby - v2 logging Plugin
Thank You
Don't forget to rate this session in the
.conf2017 mobile app