# Splunk Integration Issues

**URL:** <https://forums.suse.com/t/splunk-integration-issues/13682>\
**Category:** SUSE Rancher Prime\
**Created:** [March 20, 2019, 9:44pm UTC](https://forums.suse.com/t/splunk-integration-issues/13682 "2019-03-20T21:44:35Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![ragrawal](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@ragrawal](https://forums.suse.com/u/ragrawal)\
**Post date:** [March 20, 2019, 9:44pm UTC](https://forums.suse.com/t/splunk-integration-issues/13682/1 "2019-03-20T21:44:35Z")

</div>

Hello,  
We are facing issues with Splunk Integration for Rancher. We have the HEC token created and we are able to successfully run the curl statement against our splunk endpoint as mentioned in the document [https://rancher.com/docs/rancher/v2.x/en/tools/logging/splunk/](https://rancher.com/docs/rancher/v2.x/en/tools/logging/splunk/)  
Our container logs are getting generated and aggregated at /var/log/containers on the worker node. Our Rancher server is running on a different node other than the worker node. So when the integration to splunk is configured via the UI ( which is getting successfully saved in our case), does the logs get shipped from the node running worker or the node running the rancher server (we run a standalone rancher container).
