Splunk Enterprise Security

Is it possible to filter data coming through Elasticsearch Modular Input without changing the configuration or data indices on ES?

prachisaxena
Explorer

Hi All,

I have enabled the Modular Input for Elasticsearch(ES) and I am able to get in the data.
My sample data is metric data that was collected using Metricbeats in ES.

Looking at the data ingested in Splunk, there are a lot of fields that are coming through.
Is it possible to selectively index the data into Splunk without changing the configuration or data indices on ES?

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...