Splunk Enterprise

How can I Ingest splunk data into Elasticsearch?

cleartrail77
New Member

I create a splunk enterprise setup in a aws machine .

I can access it via http://ipv4_address_by_aws:8000

now i want to send zeek index data into elastic .

Now in elasticsearch it ask for URL of Splunk enterprise server , which I hope is   http://ipv4_address_by_aws:8000 

It asks for REST API username and password which I hope will be as splunk username and password i used during installation.

I can see data in splunk search using this command : index="zeek" source="/opt/zeek/logs/current/dns.log"

 

but this is not present in elastic after i save all these setting , I get 404 error in almost all logs

 

how to connect splunk to elastic , also this rest url , username,password is to be filled as i have defined above or any other setting

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...