<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fetching logs from Elasticsearch in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696635#M115607</link>
    <description>&lt;P&gt;Yes, still it does generate proxy logs even when fill fake settings.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mojal_0-1723985020301.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32283i6B1A8C5304A00831/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mojal_0-1723985020301.png" alt="Mojal_0-1723985020301.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem with those apps you mentioned is that they dont support authentication.&lt;/P&gt;&lt;P&gt;My Elasticsearch database is protected by authentication.&lt;/P&gt;</description>
    <pubDate>Sun, 18 Aug 2024 12:46:00 GMT</pubDate>
    <dc:creator>Mojal</dc:creator>
    <dc:date>2024-08-18T12:46:00Z</dc:date>
    <item>
      <title>Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696255#M115558</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have an Elastic DB that receive logs from various services directly and I want to send these logs to Splunk Enterprise.&lt;BR /&gt;Is there any documentation about install instruction of the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4175" target="_self"&gt;Elasticsearch Data Integrator&lt;/A&gt;?&lt;BR /&gt;I couldn't&amp;nbsp; config it to make it work and I don't find any documentation on how to install and configure this add-on.&lt;BR /&gt;&lt;BR /&gt;Please help me with that.&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161212"&gt;@larmesto&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Kind Regards,&lt;BR /&gt;Mohammad&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 09:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696255#M115558</guid>
      <dc:creator>Mojal</dc:creator>
      <dc:date>2024-08-14T09:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696318#M115568</link>
      <description>&lt;P&gt;Are you able to find working values for the inputs of the app? It seems like you can enter in your Elasticsearch domain name, port, user, secret, interval, etc, then theoretically it should pull data from your elasticsearch instance.&lt;/P&gt;&lt;P&gt;If you enter in the values but it does not work, then you could try searching your _internal index for keywords like "elasticsearch" to see if the app generates any errors that would explain why it is not pulling data from your elasticsearch instance.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 20:35:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696318#M115568</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-08-14T20:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696612#M115600</link>
      <description>&lt;P&gt;Thank you for your help&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You are correct, I did enter my elastic search information in the app but it did not pull any data.&lt;BR /&gt;&lt;BR /&gt;When I go thorough _Internal logs, I see some error logs that contains users like&amp;nbsp;&lt;SPAN&gt;&lt;U&gt;&lt;STRONG&gt;proxy&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp;&lt;/SPAN&gt;and &lt;U&gt;&lt;STRONG&gt;root&lt;/STRONG&gt;&lt;/U&gt;, but I dont have any of this users in my configs nor in my database credentials and also I didnt active the proxy option in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4175" target="_self" rel="nofollow noopener noreferrer"&gt;Elasticsearch Data Integrator&lt;/A&gt;&amp;nbsp;add-on.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mojal_0-1723963099792.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32281iDC8F02DA78147EF2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mojal_0-1723963099792.png" alt="Mojal_0-1723963099792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could mention that I can connect to elastic database via curl from splunk server which means the connection is open.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 06:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696612#M115600</guid>
      <dc:creator>Mojal</dc:creator>
      <dc:date>2024-08-18T06:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696614#M115601</link>
      <description>&lt;P&gt;As a test, does the app still complain when you add a filler proxy user+password combination in the settings?&lt;/P&gt;&lt;P&gt;There is also a different app that is often suggested for the use case of searching Elasticsearch data from Splunk. If it is not strictly necessary for you to migrate the data from Elasticsearch into Splunk, then this may be an option:&amp;nbsp;&lt;A href="https://github.com/brunotm/elasticsplunk" target="_blank"&gt;https://github.com/brunotm/elasticsplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 08:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696614#M115601</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-08-18T08:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696635#M115607</link>
      <description>&lt;P&gt;Yes, still it does generate proxy logs even when fill fake settings.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mojal_0-1723985020301.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32283i6B1A8C5304A00831/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mojal_0-1723985020301.png" alt="Mojal_0-1723985020301.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem with those apps you mentioned is that they dont support authentication.&lt;/P&gt;&lt;P&gt;My Elasticsearch database is protected by authentication.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 12:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/696635#M115607</guid>
      <dc:creator>Mojal</dc:creator>
      <dc:date>2024-08-18T12:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Fetching logs from Elasticsearch</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/697531#M115701</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271076"&gt;@Mojal&lt;/a&gt;&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263556"&gt;@marnall&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am facing the same issue with my Splunk Cluster. Were y'all able to find any workarounds/solutions?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-08-27 at 6.10.30 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32436iF345AC1D48141597/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-08-27 at 6.10.30 PM.png" alt="Screenshot 2024-08-27 at 6.10.30 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-08-27 at 6.08.27 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32435i87FE06AB6DDE51E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-08-27 at 6.08.27 PM.png" alt="Screenshot 2024-08-27 at 6.08.27 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;P.S: I have deployed the splunk cluster via splunk-operator in my kubernetes environment.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 22:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fetching-logs-from-Elasticsearch/m-p/697531#M115701</guid>
      <dc:creator>canoop</dc:creator>
      <dc:date>2024-08-27T22:11:51Z</dc:date>
    </item>
  </channel>
</rss>

