New to Splunk, trying to get data from ES to Splunk, and I was able to add "Elasticsearch Data Integrator - Modular Input", and the config seems to be fine, but how should I use the data? Any suggestion or docs?
Millions of thanks!
open search & reporting App in Splunk Enterprise.
type below in search and time range all time. check if you are seeing your ES events in Splunk.index=test