Skip to main content
Installation

Running in Docker

Keep the license fingerprint stable in a splunk/splunk container with a fixed machine-id, a persistent /opt/splunk/etc and a pinned MAC.

A license is bound to the host fingerprint, which derives from /etc/machine-id (or /sys/class/dmi/id/product_uuid) and the Splunk instance GUID ($SPLUNK_HOME/etc/instance.cfg), plus the MAC address when there is no machine-id. The official splunk/splunk image ships an empty /etc/machine-id, and the container usually has no usable MAC. 2.0.10 and earlier fail activation there; from 2.0.11 the app uses a random host ID saved in its app directory and activates normally.

That ID lives only as long as the app directory: uninstalling or deleting the app, or replacing the /opt/splunk/etc volume, changes the fingerprint. Still mount a fixed machine-id file and keep /opt/splunk/etc on a persistent volume. Splunk's own Docker deployment requires that volume anyway.

Create the machine-id file

Create it once on the Docker host, keep it and back it up. The file holds 32 lowercase hex characters.

  • Linux host: reuse the host's own /etc/machine-id, or create a dedicated one.
  • Docker Desktop (Windows, macOS): generate one.
# Linux or macOS shell, or Git Bash on Windows
python -c "import uuid; print(uuid.uuid4().hex)" > splunk-machine-id
# PowerShell
python -c "import uuid; print(uuid.uuid4().hex)" | Out-File -Encoding ascii splunk-machine-id

Do not use > in Windows PowerShell 5.1: it writes UTF-16, which the app cannot read.

You can also let a running Splunk container generate it, save it on the host and mount that file for every later container (in PowerShell, replace > with | Out-File -Encoding ascii):

docker exec splunk sh -c 'od -An -N16 -tx1 /dev/urandom | tr -d " \n"' > splunk-machine-id

Mount it in the container

Mount the file read-only over /etc/machine-id, next to a named volume for /opt/splunk/etc.

docker run -d --name splunk \
  -v /srv/splunk/machine-id:/etc/machine-id:ro \
  -v splunk-etc:/opt/splunk/etc \
  -e SPLUNK_START_ARGS=--accept-license \
  -e SPLUNK_GENERAL_TERMS=--accept-sgt-current-at-splunk-com \
  -e SPLUNK_PASSWORD=<admin-password> \
  splunk/splunk:<version>

docker-compose:

services:
  splunk:
    image: splunk/splunk:<version>
    environment:
      SPLUNK_START_ARGS: --accept-license
      SPLUNK_GENERAL_TERMS: --accept-sgt-current-at-splunk-com
      SPLUNK_PASSWORD: <admin-password>
    volumes:
      - ./splunk-machine-id:/etc/machine-id:ro
      - splunk-etc:/opt/splunk/etc
volumes:
  splunk-etc:

Writing /etc/machine-id inside a container without a mount does not survive recreating the container.

Recreate the container

docker restart keeps the fingerprint. Recreating the container (docker rm and docker run, or docker compose up after an image upgrade) keeps it only if all of these hold:

  • The same machine-id file is mounted.
  • The same /opt/splunk/etc volume is reused.
  • Without a mounted machine-id, if the container can read a real MAC (host networking, or an image with network tools), the fingerprint depends on it: pin it with --mac-address (compose: mac_address:), or use host networking every time. With the machine-id mounted, a changing MAC does not matter.

2.0.10 and earlier always counted a readable MAC, machine-id or not. Hosts activated on those versions keep their old binding after the upgrade; from 2.0.12 an online license moves them to the current fingerprint within the same node about 5 minutes after the upgrade.

Lose any one of these and the fingerprint changes, locking paid features. Re-activate an online license, or ask support to rebind an offline one.

Check the fingerprint

On the License page, the Host fingerprint card shows the value this container computes (Host identifier · for reference). It stays the same across restarts and upgrades.

If the card shows "This host has no readable hardware fingerprint (no machine-id inside the container)", an offline license cannot be bound to this container: mount a machine-id as described above and recreate the container.

On this page