splunk-lab
splunk-lab copied to clipboard
Universal Forwarder Support
Since Splunk 8.0 has added to the Universal Forwarder a bit, I should add in support for a Universal Forwarder, specifically:
- A separate Docker Image (may need to build parallel to
splunk-lab-core) - A separate
docker-compose.ymlfile that loads both Splunk Lab and the UF - A separate starting script which will download a
docker-compose.ymland have the UF read fromlogs/and forwarded to Splunk.