Searching OpenSearch from Splunk Enterprise (software)

0

(couldn't find this in the existing posts)

I am looking for feedback on how others have successfully allowed Splunk Enterprise (aka software) to query an OpenSearch cluster? I have come across to Splunk Add-Ons, but looking for any successes, war stories, or alternative approaches.

  1. ElasticSPL Add-on for Splunk -- https://splunkbase.splunk.com/app/6477 Datapunctum ElasticSPL enables Splunk users to query data stored in Elasticsearch without switching tools. The comprehensive feature set supports both time-series and aggregated DSL queries and provides a powerful, intuitive interface for exploring data. See Documentation at docs.datapunctum.com/elasticspl Keywords: Elasticsearch, Elastic, OpenDistro, OpenSearch, ELK, Kibana

  2. Elasticsearch Data Integrator - Modular Input - https://splunkbase.splunk.com/app/4175 This Add-On allows pulling data from Elasticsearch to Splunk. Now you can search through Elasticsearch indices using the power of Splunk SPL language.

The former explicitly mentions OpenSearch whereas the latter is explicitly ElasticSearch. I haven't been able to confirm if it would or would not work with OpenSearch based upon its Elastic 7.10 fork / compatibility.

已提問 3 個月前檢視次數 365 次
沒有答案

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南