Deployment Overview of Splunk Enterprise (free trial) on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: A Linux-based system with Docker installed.
-
Privileges: Root or sudo access is required for service management and directory creation.
-
Docker Service: The
dockerservice must be installed, enabled, and running. -
Network Ports:
-
Port
80/tcp(for SSL certificate verification). -
Port
443/tcp(for secure HTTPS access). -
Port
8000/tcp(internal application access).
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific Fully Qualified Domain Name (FQDN) based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | splunk |
| Domain | hostkey.in |
| Full template | splunk{Server_ID}.hostkey.in |
File and Directory Structure¶
The application files and configurations are organized as follows:
-
/root/splunk/: Main deployment directory containing the orchestration configuration. -
/root/splunk/compose.yml: Docker Compose file used to manage containers. -
/data/nginx/user_conf.d/: Directory containing Nginx proxy and SSL configuration files. -
nginx_secrets(Docker Volume): External volume used for storing Let's Encrypt SSL certificates.
Application Installation Process¶
The installation is performed using Docker Compose to orchestrate the application and its reverse proxy. The process follows these steps:
-
System Preparation: The system ensures that the Docker engine is installed, started, and enabled on boot.
-
Directory Setup: A dedicated directory
/root/splunkis created with0644permissions for the root user. -
Configuration Generation: A
compose.ymlfile is generated in the deployment directory to define the service stack. -
Container Deployment: The containers are started in detached mode using the following command within the
/root/splunkdirectory:
Docker Containers and Their Deployment¶
The application utilizes two primary containers managed via Docker Compose.
Nginx Proxy Container¶
-
Image:
jonasal/nginx-certbot:latest -
Ports:
-
80:80(HTTP) -
443:443(HTTPS) -
Volumes:
-
nginx_secrets:/etc/letsencrypt -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d -
Environment Variables:
-
Restart Policy:
unless-stopped
Splunk Container¶
-
Image:
splunk/splunk:latest -
Ports:
-
8000:8000(Internal application port) -
Environment Variables:
-
SPLUNK_START_ARGS=--accept-license -
SPLUNK_PASSWORD=[REDACTED] -
Restart Policy:
unless-stopped
Custom Scripts and Additional Setup¶
Following the container deployment, the following configuration adjustments are performed:
-
Nginx Proxy Configuration: The Nginx configuration file located at
/data/nginx/user_conf.d/{prefix}{Server_ID}.{zone}.confis modified to route traffic from the external domain to the internal Splunk service viahttp://splunk:8000. -
SSL Integration: Certbot is utilized within the Nginx container to obtain and manage SSL certificates for the configured FQDN.
Application Update Instructions¶
To update the main application, navigate to the deployment directory and pull the latest images before restarting the services:
Location of Configuration Files and Data¶
-
Docker Orchestration:
/root/splunk/compose.yml -
Nginx Configurations:
/data/nginx/user_conf.d/ -
SSL Certificates: Managed via the
nginx_secretsDocker volume.
Available Ports for Connection¶
| Port | Protocol | Purpose |
|---|---|---|
| 80 | TCP | HTTP (Certbot validation) |
| 443 | TCP | HTTPS (Secure Web Access) |
| 8000 | TCP | Internal Application Interface |
Starting and Stopping the Application¶
The application is managed using Docker Compose commands from the /root/splunk directory.
To start the application:
To stop the application: