Docker容器中Splunk Universal Forwarder启动错误求助
Splunk Universal Forwarder Docker启动错误排查
问题详情
运行命令
docker run -d -p 9997:9997 -p 8080:8080 -p 8089:8089 -e "SPLUNK_START_ARGS=--accept-license" -e "SPLUNK_PASSWORD=test12345" --name uf splunk/universalforwarder:latest
启动错误日志
2025-03-05 14:47:58 included: /opt/ansible/roles/splunk_universal_forwarder/tasks/../../../roles/splunk_common/tasks/check_for_required_restarts.yml for localhost 2025-03-05 14:47:58 Wednesday 05 March 2025 09:17:58 +0000 (0:00:00.044) 0:00:30.316 ******* 2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (5 retries left). 2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (4 retries left). 2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (3 retries left). 2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (2 retries left). 2025-03-05 14:48:31 FAILED - RETRYING: [localhost]: Check for required restarts (1 retries left). 2025-03-05 14:48:31 2025-03-05 14:48:31 TASK [splunk_universal_forwarder : Check for required restarts] **************** 2025-03-05 14:48:31 fatal: [localhost]: FAILED! => { 2025-03-05 14:48:31 "attempts": 5, 2025-03-05 14:48:31 "changed": false, 2025-03-05 14:48:31 "changed_when_result": "The conditional check 'restart_required.status == 200' failed. The error was: error while evaluating conditional (restart_required.status == 200): 'dict object' has no attribute 'status'. 'dict object' has no attribute 'status'" 2025-03-05 14:48:31 } 2025-03-05 14:48:31 2025-03-05 14:48:31 MSG: 2025-03-05 14:48:31 2025-03-05 14:48:31 GET/services/messages/restart_required?output_mode=jsonadmin********8089NoneNoneNone[200, 404];;; failed with NO RESPONSE and EXCEP_STR as Not supported URL scheme http+unix
已做排查
- Splunkd运行状态正常,端口均已开放
- 尝试执行
curl http://localhost:8089/services/messages/restart_required?output_mode=json验证API连接
解决方案
从日志中的Not supported URL scheme http+unix可以定位问题:Ansible角色尝试用Unix套接字协议连接Splunk API,但当前环境不支持该协议。可按以下步骤处理:
禁用Ansible的Unix套接字连接
在Ansible变量中添加splunk_use_http_unix_socket: false,强制角色通过8089端口使用HTTP协议连接Splunk API,绕过Unix套接字的兼容问题。验证容器内Splunk API配置
进入容器:docker exec -it uf bash检查web配置中的端口设置:
cat $SPLUNK_HOME/etc/system/local/web.conf | grep httpPort确认
httpPort为8089,若配置错误则修改后重启Splunk:$SPLUNK_HOME/bin/splunk restart确认端口映射有效性
检查宿主机与容器的8089端口映射是否生效,容器内端口是否被正常监听:docker exec uf netstat -tulpn | grep 8089若端口未监听,重新启动容器并确保启动命令中的
-p 8089:8089参数正确。更新Splunk Ansible角色
旧版本角色可能存在Unix套接字的兼容性bug,更新到最新版本可修复此类问题。
内容的提问来源于stack exchange,提问作者K. Sam Ashray
相关产品推荐
相关产品推荐

