All Apps and Add-ons

What is the difference between the Kafka Messaging Modular Input and the Splunk Add-on for Kafka?

maximus_reborn
Path Finder

Maybe this question sounds naive, but what is the difference between both the Kafka Messaging Modular Input and the Splunk Add-on for Kafka?
I believe both are for extracting the messages from broker and indexing it. Can anyone please correct me if I am wrong?

Also, how do I configure the Kafka Messaging Modular Input developed by Damien? I have not found any clear documentation pertaining to its configuration.

0 Karma
1 Solution

a212830
Champion

Looks to me like the Splunk add-on is for monitoring the performance of Kafaka, but the modular input is used to index data from kafka.

Personally, I'd like to see a streaming modular input, which allows me to read it, without indexing it (and maybe I'll win the lottery, right?)

View solution in original post

0 Karma

a212830
Champion

Looks to me like the Splunk add-on is for monitoring the performance of Kafaka, but the modular input is used to index data from kafka.

Personally, I'd like to see a streaming modular input, which allows me to read it, without indexing it (and maybe I'll win the lottery, right?)

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

The Splunk supported add-on is also able to index Kafka payloads. http://docs.splunk.com/Documentation/AddOns/latest/Kafka/Configuremodularinputs

maximus_reborn
Path Finder

Thanks jcoates for the reply. So I have configured kafka add-on from CLI. But can you tell me the command to run it in SplunkWeb GUI.

Also,
Can I able to write correlation rules on it?
Basically I have 30 kafka topics that is to be streamed into splunk. My aim is only to insert the payload in splunk and have correlation rules on it.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...