Splunk Supporting Add-on for Elasticsearch (ElasticSPL) provides a straightforward way of querying data stored in Elasticsearch from Splunk using custom Splunk commands.
ElasticSPL provides the following functionality to Splunk users:
In addition, ElasticSPL provides an admin section that allows the management of multiple Elasticsearch instances and saved queries. Finally, a comprehensive access control system based on Splunk capabilities and roles allows for granular access control from Splunk to Elasticsearch.
ElasticSPL is compatible with the following flavours of Elasticsearch:
- Elasticsearch 8
- Elasticsearch 7
- Elasticsearch 6
- OpenDistro
- OpenSearch
Keywords: Elasticsearch, Elastic, OpenDistro, OpenSearch, ELK, Kibana
Fixed issues:
Fixed issues:
Please see Upgrade Notes for more details.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.