Splunk Enterprise

How can I Ingest splunk data into Elasticsearch?

cleartrail77
New Member

I create a splunk enterprise setup in a aws machine .

I can access it via http://ipv4_address_by_aws:8000

now i want to send zeek index data into elastic .

Now in elasticsearch it ask for URL of Splunk enterprise server , which I hope is   http://ipv4_address_by_aws:8000 

It asks for REST API username and password which I hope will be as splunk username and password i used during installation.

I can see data in splunk search using this command : index="zeek" source="/opt/zeek/logs/current/dns.log"

 

but this is not present in elastic after i save all these setting , I get 404 error in almost all logs

 

how to connect splunk to elastic , also this rest url , username,password is to be filled as i have defined above or any other setting

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...