As already asked we need more information to your needs and especially your business case! Yes, it's possible to use kafka as an output target in Splunk HF. But why you want to use it and is there any other way to achieve Splunk -> ElasticSearch which is cheaper and has less moving parts and follow KISS principle? Then if not, which kafka installation you are using? Some open source, Confluent, Aiven or something else. And are you sending a new events which you also ingesting into splunk or are you ingesting those with UF/HF and only target is ES via Kafka. Or are you getting some events for Splunk which have already indexed? And your environment: OS, Splunk, etc.
... View more