I'mg looking for a way to ingest data from HDFS data into Splunk Enterprise, and found several blog posts pointing to the Hadoop Connect app. Unfortunately, that seems to have been deleted (getting a 404 error). Does anyone know what happened to the app, or if there is some other way to ingest data from HDFS into Splunk 6.5?
Do you need to ingest the data, or can you do what you need to do just by searching the data in HDFS? If you just need to use SPL to search your Hadoop, data, then you can use the virtual index and Hadoop analytics features in Splunk Enterprise 6.5. See the Splunk Analytics for Hadoop documentation.
Although this isn't the answer I was hoping to find, I appreciated the response nonetheless. It's frustrating that, rather than download an already created free app, my only option would now seem to be spending $3k+. I'll set this as the accepted solution however, as it would seem to be the only way to accomplish what I'm looking to do. Thanks for your time.