![]() |
VOOZH | about |
Elasticsearch is a popular distributed full-text search engine. By centrally storing data, you can perform ultra-fast searches, fine-tuning relevance, and powerful analytics with ease. Elasticsearch has a pipeline tool for loading data called "Logstash". You can use CData JDBC Drivers to easily import data from any data source into Elasticsearch for search and analysis.
This article explains how to use the CData JDBC Driver for Splunk to load data from Splunk into Elasticsearch via Logstash.
Now, let's create a configuration file for Logstash to transfer Splunk data to Elasticsearch.
To authenticate requests, set the , , and properties to valid Splunk credentials. The port on which the requests are made to Splunk is port 8089.
The data provider uses plain-text authentication by default, since the data provider attempts to negotiate TLS/SSL with the server.
If you need to manually configure TLS/SSL, see Getting Started -> Advanced Settings in the data provider help documentation.
Now let's run Logstash using the created "logstash.conf" file.
logstash-7.8.0\bin\logstash -f logstash.conf
A log indicating success will appear. This means the Splunk data has been loaded into Elasticsearch.
For example, let's view the data transferred to Elasticsearch in Kibana.
GET splunk_table/_search
{
"query": {
"match_all": {}
}
}
👁 Querying the Splunk data loaded into ElasticsearchWe have confirmed that the data is stored in Elasticsearch.
👁 Confirming the Splunk data loaded into ElasticsearchBy using the CData JDBC Driver for Splunk with Logstash, it functions as a Splunk connector, making it easy to load data into Elasticsearch. Please try the 30-day free trial.
Download a free trial of the Splunk Driver to get started:
Download NowLearn more:
👁 Splunk IconRapidly create and deploy powerful Java applications that integrate with Splunk data including Datamodels, Datasets, SearchJobs, and more!