<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting data from Elastic Search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185642#M186995</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Can you share sample scripts  or configuration setting for me to get data from elastic search in an incremental manner? &lt;/P&gt;

&lt;P&gt;The source data is information about event with updated_at to get the incremental information. Other attributes include event_name, event_location, event_start_time, event_end_time&lt;/P&gt;

&lt;P&gt;thanks, ronak&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 18:38:54 GMT</pubDate>
    <dc:creator>ronak</dc:creator>
    <dc:date>2020-09-28T18:38:54Z</dc:date>
    <item>
      <title>Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185642#M186995</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Can you share sample scripts  or configuration setting for me to get data from elastic search in an incremental manner? &lt;/P&gt;

&lt;P&gt;The source data is information about event with updated_at to get the incremental information. Other attributes include event_name, event_location, event_start_time, event_end_time&lt;/P&gt;

&lt;P&gt;thanks, ronak&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185642#M186995</guid>
      <dc:creator>ronak</dc:creator>
      <dc:date>2020-09-28T18:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185643#M186996</link>
      <description>&lt;P&gt;Could you provide more information on what you need here? Is the data already indexed and you just want to search and get the latest/updated incremental data?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 18:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185643#M186996</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-01-16T18:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185644#M186997</link>
      <description>&lt;P&gt;hi - Yes, the data resides in ES. &lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 20:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185644#M186997</guid>
      <dc:creator>ronak</dc:creator>
      <dc:date>2015-01-16T20:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185645#M186998</link>
      <description>&lt;P&gt;Not sure what you are trying to do, but you could ship the data you already have to Elasticsearch to Splunk simultaneously. I'm doing this to evaluate both products. &lt;/P&gt;

&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 20:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185645#M186998</guid>
      <dc:creator>chrisboy68</dc:creator>
      <dc:date>2015-01-16T20:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185646#M186999</link>
      <description>&lt;P&gt;Chris &lt;/P&gt;

&lt;P&gt;Some system, that can send data to one destination , in my enterprise has already sent data to ES. My objective is to extract the data from ES and give to splunk for indexing. &lt;/P&gt;

&lt;P&gt;I'm looking for a template script or configuration that someone might have already done to extract data from ES ...&lt;/P&gt;

&lt;P&gt;Hope this helps clarify&lt;/P&gt;

&lt;P&gt;appreciate any pointers&lt;/P&gt;

&lt;P&gt;thanks, ronak&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 20:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185646#M186999</guid>
      <dc:creator>ronak</dc:creator>
      <dc:date>2015-01-16T20:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185647#M187000</link>
      <description>&lt;P&gt;Hi Ronak,&lt;/P&gt;

&lt;P&gt;we are facing the same situation, would like to got  ALL syslog data from elastich search to Spunk.&lt;BR /&gt;
You have been able to solve the issue&lt;/P&gt;

&lt;P&gt;Many txs in advance&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 13:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185647#M187000</guid>
      <dc:creator>pedro50</dc:creator>
      <dc:date>2015-09-28T13:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185648#M187001</link>
      <description>&lt;P&gt;I agree with Chris on this. Anyone looking to do this would be better off installing a UF (or HF) on the same data source that ES is using (e.g. syslog server). Even if you had an easy way to port data from ES to Splunk, you would be introducing a new point of failure, and would inherit any issues ES has with data integrity, availability, etc.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 14:12:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185648#M187001</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2015-09-28T14:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185649#M187002</link>
      <description>&lt;P&gt;I found this ... not sure if/how it works &lt;A href="http://devpost.com/software/splunk-elasticsearch"&gt;http://devpost.com/software/splunk-elasticsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 15:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185649#M187002</guid>
      <dc:creator>wsnyder2</dc:creator>
      <dc:date>2016-05-24T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting data from Elastic Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185650#M187003</link>
      <description>&lt;P&gt;This might be helpful for anyone visiting; I have started working on an addon for Elasticsearch instances, feel free to use it!&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4175/"&gt;https://splunkbase.splunk.com/app/4175/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 18:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-data-from-Elastic-Search/m-p/185650#M187003</guid>
      <dc:creator>larmesto</dc:creator>
      <dc:date>2018-09-25T18:50:34Z</dc:date>
    </item>
  </channel>
</rss>

