You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器中Splunk Universal Forwarder启动错误求助

Splunk Universal Forwarder Docker启动错误排查

问题详情

运行命令

docker run -d   -p 9997:9997   -p 8080:8080   -p 8089:8089   -e "SPLUNK_START_ARGS=--accept-license"  -e "SPLUNK_PASSWORD=test12345"   --name uf   splunk/universalforwarder:latest

启动错误日志

2025-03-05 14:47:58 included: /opt/ansible/roles/splunk_universal_forwarder/tasks/../../../roles/splunk_common/tasks/check_for_required_restarts.yml for localhost
2025-03-05 14:47:58 Wednesday 05 March 2025  09:17:58 +0000 (0:00:00.044)       0:00:30.316 *******
2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (5 retries left).
2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (4 retries left).
2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (3 retries left).
2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (2 retries left).
2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (1 retries left).
2025-03-05 14:48:31
2025-03-05 14:48:31 TASK [splunk_universal_forwarder : Check for required restarts] ****************
2025-03-05 14:48:31 fatal: [localhost]: FAILED! => {
2025-03-05 14:48:31     "attempts": 5,
2025-03-05 14:48:31     "changed": false,
2025-03-05 14:48:31     "changed_when_result": "The conditional check 'restart_required.status == 200' failed. The error was: error while evaluating conditional (restart_required.status == 200): 'dict object' has no attribute 'status'. 'dict object' has no attribute 'status'"
2025-03-05 14:48:31 }
2025-03-05 14:48:31
2025-03-05 14:48:31 MSG:
2025-03-05 14:48:31
2025-03-05 14:48:31 GET/services/messages/restart_required?output_mode=jsonadmin********8089NoneNoneNone[200, 404];;; failed with NO RESPONSE and EXCEP_STR as Not supported URL scheme http+unix

已做排查

  • Splunkd运行状态正常,端口均已开放
  • 尝试执行curl http://localhost:8089/services/messages/restart_required?output_mode=json验证API连接

解决方案

从日志中的Not supported URL scheme http+unix可以定位问题:Ansible角色尝试用Unix套接字协议连接Splunk API,但当前环境不支持该协议。可按以下步骤处理:

  1. 禁用Ansible的Unix套接字连接
    在Ansible变量中添加splunk_use_http_unix_socket: false,强制角色通过8089端口使用HTTP协议连接Splunk API,绕过Unix套接字的兼容问题。

  2. 验证容器内Splunk API配置
    进入容器:

    docker exec -it uf bash
    

    检查web配置中的端口设置:

    cat $SPLUNK_HOME/etc/system/local/web.conf | grep httpPort
    

    确认httpPort为8089,若配置错误则修改后重启Splunk:

    $SPLUNK_HOME/bin/splunk restart
    
  3. 确认端口映射有效性
    检查宿主机与容器的8089端口映射是否生效,容器内端口是否被正常监听:

    docker exec uf netstat -tulpn | grep 8089
    

    若端口未监听,重新启动容器并确保启动命令中的-p 8089:8089参数正确。

  4. 更新Splunk Ansible角色
    旧版本角色可能存在Unix套接字的兼容性bug,更新到最新版本可修复此类问题。


内容的提问来源于stack exchange,提问作者K. Sam Ashray

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 03:27:38