Skip to content

Deployment Overview of Splunk Enterprise (free trial) on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the following requirements must be met:

  • Operating System: A Linux-based system with Docker installed.

  • Privileges: Root or sudo access is required for service management and directory creation.

  • Docker Service: The docker service must be installed, enabled, and running.

  • Network Ports:

  • Port 80/tcp (for SSL certificate verification).

  • Port 443/tcp (for secure HTTPS access).

  • Port 8000/tcp (internal application access).

FQDN of the final panel on the hostkey.in domain

The application is accessible via a specific Fully Qualified Domain Name (FQDN) based on the server ID.

Parameter Value
Prefix splunk
Domain hostkey.in
Full template splunk{Server_ID}.hostkey.in

File and Directory Structure

The application files and configurations are organized as follows:

  • /root/splunk/: Main deployment directory containing the orchestration configuration.

  • /root/splunk/compose.yml: Docker Compose file used to manage containers.

  • /data/nginx/user_conf.d/: Directory containing Nginx proxy and SSL configuration files.

  • nginx_secrets (Docker Volume): External volume used for storing Let's Encrypt SSL certificates.

Application Installation Process

The installation is performed using Docker Compose to orchestrate the application and its reverse proxy. The process follows these steps:

  1. System Preparation: The system ensures that the Docker engine is installed, started, and enabled on boot.

  2. Directory Setup: A dedicated directory /root/splunk is created with 0644 permissions for the root user.

  3. Configuration Generation: A compose.yml file is generated in the deployment directory to define the service stack.

  4. Container Deployment: The containers are started in detached mode using the following command within the /root/splunk directory:

docker compose up -d

Docker Containers and Their Deployment

The application utilizes two primary containers managed via Docker Compose.

Nginx Proxy Container

  • Image: jonasal/nginx-certbot:latest

  • Ports:

  • 80:80 (HTTP)

  • 443:443 (HTTPS)

  • Volumes:

  • nginx_secrets:/etc/letsencrypt

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d

  • Environment Variables:

  • [email protected]

  • Restart Policy: unless-stopped

Splunk Container

  • Image: splunk/splunk:latest

  • Ports:

  • 8000:8000 (Internal application port)

  • Environment Variables:

  • SPLUNK_START_ARGS=--accept-license

  • SPLUNK_PASSWORD=[REDACTED]

  • Restart Policy: unless-stopped

Custom Scripts and Additional Setup

Following the container deployment, the following configuration adjustments are performed:

  1. Nginx Proxy Configuration: The Nginx configuration file located at /data/nginx/user_conf.d/{prefix}{Server_ID}.{zone}.conf is modified to route traffic from the external domain to the internal Splunk service via http://splunk:8000.

  2. SSL Integration: Certbot is utilized within the Nginx container to obtain and manage SSL certificates for the configured FQDN.

Application Update Instructions

To update the main application, navigate to the deployment directory and pull the latest images before restarting the services:

cd /root/splunk
docker compose pull && docker compose up -d

Location of Configuration Files and Data

  • Docker Orchestration: /root/splunk/compose.yml

  • Nginx Configurations: /data/nginx/user_conf.d/

  • SSL Certificates: Managed via the nginx_secrets Docker volume.

Available Ports for Connection

Port Protocol Purpose
80 TCP HTTP (Certbot validation)
443 TCP HTTPS (Secure Web Access)
8000 TCP Internal Application Interface

Starting and Stopping the Application

The application is managed using Docker Compose commands from the /root/splunk directory.

To start the application:

docker compose up -d

To stop the application:

docker compose down

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×