Splunk Operator for Kubernetes overview
Deploy and manage Splunk Enterprise on Kubernetes with the Splunk Operator for Kubernetes (SOK).
The Splunk Operator for Kubernetes (SOK) provides automated lifecycle management for Splunk Enterprise on Kubernetes. Using the Kubernetes operator pattern and Splunk-specific custom resources, SOK helps you deploy, scale, and maintain resilient Splunk Enterprise environments.
This guide is for Splunk platform administrators who deploy and manage Splunk Enterprise with SOK.
Get started with SOK
- Review Kubernetes platform options in Platform recommendations.
- Verify Splunk Enterprise and Kubernetes release versions in Splunk Operator compatibility matrix.
- Check infrastructure prerequisites in Hardware requirements, Storage guidelines, and Docker images.
- Plan for security before you deploy in Secure Splunk Operator deployments.
- Install SOK using Helm charts or manifest files. See Install the Splunk Operator.
- Deploy a single Splunk Enterprise instance in Create a Splunk Enterprise deployment.
See also
For more advanced Splunk Enterprise configuration examples (clustered deployments, license managers, and more), see Configure Splunk Enterprise - Examples.
For support information, see Splunk Operator support resources.