Splunk Search

How to import elasticsearch logs into Splunk?

sdurao
Engager

Hi

We have log from an Elasticsearch syslog. And we want to import these logs into Splunk.
How can i do that ?

I would have done like this:
- modify the /opt/splunk/etc/deployment-apps/cg93_all_uf_syslog_inputs/local/file and add
[udp://number_port]
sourcetype = elastic
index = switch_logs

Is that correct?

Thanks

Sham

0 Karma

larmesto
Path Finder

This might be helpful for anyone visiting; I have started working on an addon for Elasticsearch instances, feel free to use it!
https://splunkbase.splunk.com/app/4175/

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...