criblio / cribl-demo Goto Github PK
View Code? Open in Web Editor NEWCribl Demo Content
Cribl Demo Content
See dns panel in attached screenshot - this relates to #6
It is referenced in the enrich pipeline, but it is missing in functions
Hey there,
I found your Git repo while doing a Google Search on cribl while getting a demo at work and found it interesting that you implemented Splunk in Docker, because so have I!
My project is over at https://github.com/dmuth/splunk-lab and I see that yours is more just installing just the universal forwarder whereas mine is more about creating a full blown install of Splunk with some apps installed.
That said, if you're interested in comparing notes, there might be an opportunity for us save each other some effort. :-) Do let me know if you're interested. Thanks!
-- Doug
For some reason that i can't find in the code, the worker nodes are coming up as cribl 2, but the master node is coming up as cribl 1.7.2
docker-compose logs:
cribl-w1_1 | {"time":"2019-10-19T09:04:45.299Z","channel":"cribl","cid":"api","level":"info","message":"API server started","VERSION":"42.0-260d8083","BRANCH":"master","TIMESTAMP":"2019-10-18T17:47:45.445Z"}
cribl_1 | {"time":"2019-10-19T09:04:46.969Z","channel":"cribl","level":"info","message":"API server started","VERSION":"1.7.2-b7b4759d","BRANCH":"undefined","TIMESTAMP":"2019-10-14T16:15:30.329Z"}
From what I can tell by the Dockerfile and the docker-compose file, the Dockerfile is using cribl/cribl:next
and the docker-compose file is using context: cribl
Any ideas how this could be happening?
I've done a system prune and everything and removed all volumes also so it -should- be a clean system.
Similar to training build I'm putting in now, it would be nice to be able to create lighter configurations of the demo with a build system.
The sandbox URL sent in the email uses https:// while the settings in cribl.yml
has SSL disabled
The dashboards inside Splunk's dashboards in demo app use https:// as well
Hey, can you switch to ARM64 container images instead of x86-64 for the M1 macs? It runs much more faster using native platform docker images compared to x86-64.
Log is here:
https://pastebin.com/gcGEkW3Y
the cribl Dockerfile seems to be referring to a new entrypoint.sh which does not exist. This configuration is different to the master branch.
docker-compose up -d
WARNING: The ELK_VERSION variable is not set. Defaulting to a blank string.
Building cribl-w0
Step 1/11 : FROM cribl/cribl:next
---> 54ac8ddaf089
Step 2/11 : COPY http_status.csv /opt/cribl/data/lookups/http_status.csv
---> Using cache
---> a15a32040c38
Step 3/11 : COPY scripts/ /opt/cribl/scripts/
---> Using cache
---> ee2c6128a2aa
Step 4/11 : ADD http://cdn.cribl.io/dl/scope/latest/linux/libwrap.so /usr/lib/libwrap.so
---> Using cache
---> e077babd1740
Step 5/11 : RUN chmod 755 /usr/lib/libwrap.so
---> Using cache
---> 90f096c1f7ad
Step 6/11 : ENV SCOPE_OUT_DEST=udp://localhost:8125
---> Using cache
---> 22b72b4d71a4
Step 7/11 : ENV SCOPE_LOG_LEVEL=info
---> Using cache
---> 726464b6b62c
Step 8/11 : ENV SCOPE_LOG_DEST=file:///tmp/scope.log
---> Using cache
---> 19005a1428f0
Step 9/11 : ENV SCOPE_OUT_VERBOSITY=4
---> Using cache
---> 71109b796423
Step 10/11 : ENV GIT_DISCOVERY_ACROSS_FILESYSTEM=1
---> Using cache
---> bd40e1790a4e
Step 11/11 : ADD entrypoint.sh /sbin/entrypoint.sh
ERROR: Service 'cribl-w0' failed to build: ADD failed: stat /var/lib/docker/tmp/docker-builder896508838/entrypoint.sh: no such file or directory
I followed the proecudure and start Mac Os X steps gives below error:
parsing skaffold config: failed to apply profiles to config "cribl-demo" defined in file "/Users/tulpar/Project/cribl-demo/skaffold.yaml": applying profile "dev": invalid path: /deploy/kubectl/manifests/12. There's an issue with one of the profiles defined in config "cribl-demo" in file "/Users/tulpar/Project/cribl-demo/skaffold.yaml"; refer to the documentation on how to author valid profiles: https://skaffold.dev/docs/environment/profiles/.
FYI the Cribl demo license expired.
workaround:
AppScope 1.0 defined a baseline for schema. Several changes were made in order to standardize the schema. We need to make changes and validate as needed.
Hi all,
after updating to the latest version on master branch (version tag v1.7-118-gec1ea57) I am getting the following error when executing the start.sh script:
./start.sh: line 9: ./scope: No such file or directory
error: no objects passed to apply
Am I missing something or is that a bug?
Kind regards
Chris
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.