Splunk
Splunk aims to help users quickly and securely deploy and manage Splunk related services in a containerized environment. It supports multiple security and rights configurations and is suitable for production environments and development test scenarios.
You need to create an administrator account password for the first time to enter ·Easily deploy and run Splunk services in containers ·Support multiple boot users (splunk, ansible, root), flexibly meeting different security requirements and permission settings ·It is recommended to run as a non-privileged user (splunk) by default to improve the security of the production environment ·Allow you to customize running users and user groups through environment variables and configuration files to adapt to different log reading and writing requirements ·Support the use of security contexts (such as fsGroup) under orchestration platforms such as Kubernetes to improve persistent volume access security ·Provides optional privileged features such as automatic installation of OpenJDK and automatic verification of SPLUNK_HOME directory permissions ·Detailed security policies and configuration instructions to help users prevent privilege escalation and data leakage risks ·Suitable for multiple enterprise-level scenarios such as log collection, data analysis and security compliance

