We have client with splunk enterprise instance and we need to send some logs from this instance directly to elasticsearch .
Is it possible!?
Is there a reason why you don't want to use the solution you already know, ie putting logstash in the middle?
That being said, do describe what you're actually looking for. Examples: Send some historical logs from Splunk elsewhere (manually, automated)? Send new logs that come into Splunk elsewhere (storing in Splunk / copying, or sending elsewhere instead of storing in Splunk)?