Splunk Enterprise

How can I Ingest splunk data into Elasticsearch?

cleartrail77
New Member

I create a splunk enterprise setup in a aws machine .

I can access it via http://ipv4_address_by_aws:8000

now i want to send zeek index data into elastic .

Now in elasticsearch it ask for URL of Splunk enterprise server , which I hope is   http://ipv4_address_by_aws:8000 

It asks for REST API username and password which I hope will be as splunk username and password i used during installation.

I can see data in splunk search using this command : index="zeek" source="/opt/zeek/logs/current/dns.log"

 

but this is not present in elastic after i save all these setting , I get 404 error in almost all logs

 

how to connect splunk to elastic , also this rest url , username,password is to be filled as i have defined above or any other setting

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...