All Apps and Add-ons

How to forward data from Elasticsearch to Splunk?

nareerat_pr
Explorer

I would like to forward data from Elasticsearch to Splunk, but was not able to get a proper solution.
I found the "Elasticsearch Data Integrator - Modular Input" Add-on in Splunkbase (https://splunkbase.splunk.com/app/4175/), it seems to be fine, but I want to filter only important data for each Elasticsearch Indice before sending it to Splunk, Can you recommend the other solution to get data from Elasticsearch, and please do let me know the steps or reference document also.

Labels (2)
0 Karma

The_Simko
Path Finder

Your built-in choices are:
1. Adjust the modular input so it only requests what you want
2. Use ingest_eval to eliminate the elements you don't need.

DSP and some third-party elements are also possible. 

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...