Could you please share your experience, are these 2 solutions reliable as an instument for data input?
Like splunk dbconnect, for example.
Thanks in advance.
From what I have made :
I query elasticsearch via python scripts, then I route the results to the Python script.
And I deposit the script.py on the bin of my application. And there you can call it easily.
Imane El Mostaad,
I have used this and it works really well so far in Splunk 7.1:
it adds a new command
ess that allows you to specify one or more nodes to search against. It provides results back using the statistics model (sorta like using db connect to query a db directly).