Splunk Enterprise

How can I Ingest splunk data into Elasticsearch?

cleartrail77
New Member

I create a splunk enterprise setup in a aws machine .

I can access it via http://ipv4_address_by_aws:8000

now i want to send zeek index data into elastic .

Now in elasticsearch it ask for URL of Splunk enterprise server , which I hope is   http://ipv4_address_by_aws:8000 

It asks for REST API username and password which I hope will be as splunk username and password i used during installation.

I can see data in splunk search using this command : index="zeek" source="/opt/zeek/logs/current/dns.log"

 

but this is not present in elastic after i save all these setting , I get 404 error in almost all logs

 

how to connect splunk to elastic , also this rest url , username,password is to be filled as i have defined above or any other setting

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...