Skip to content

Universal Forwarder Support #3

@dmuth

Description

@dmuth

Since Splunk 8.0 has added to the Universal Forwarder a bit, I should add in support for a Universal Forwarder, specifically:

  • A separate Docker Image (may need to build parallel to splunk-lab-core)
  • A separate docker-compose.yml file that loads both Splunk Lab and the UF
  • A separate starting script which will download a docker-compose.yml and have the UF read from logs/ and forwarded to Splunk.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions