Splunk Enterprise

How can I Ingest splunk data into Elasticsearch?

cleartrail77
New Member

I create a splunk enterprise setup in a aws machine .

I can access it via http://ipv4_address_by_aws:8000

now i want to send zeek index data into elastic .

Now in elasticsearch it ask for URL of Splunk enterprise server , which I hope is   http://ipv4_address_by_aws:8000 

It asks for REST API username and password which I hope will be as splunk username and password i used during installation.

I can see data in splunk search using this command : index="zeek" source="/opt/zeek/logs/current/dns.log"

 

but this is not present in elastic after i save all these setting , I get 404 error in almost all logs

 

how to connect splunk to elastic , also this rest url , username,password is to be filled as i have defined above or any other setting

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...