Elasticsearch Data Integrator - Modular Input

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
funderburg78
Posts: 1
Joined: Mon Feb 08, 2021 11:20 am

Elasticsearch Data Integrator - Modular Input

Post by funderburg78 »

https://splunkbase.splunk.com/app/4175/

Has anyone attempted to use the above connector to get data from Nagios to Splunk? I have a Also, anyone know if there is an easy way to parse data so that devices with seperate data formats can be input as different sourcetypes into splunk?
User avatar
cdienger
Support Tech
Posts: 5045
Joined: Tue Feb 07, 2017 11:26 am

Re: Elasticsearch Data Integrator - Modular Input

Post by cdienger »

Welcome to the forums, @funderburg78!

I'm not aware of anyone using the component you've linked to, but it is possible to create an output in NLS that will send logs to a remote Splunk server:

https://support.nagios.com/forum/viewto ... 38&t=47443

A grok filter can be set up to parse the log lines and set a tag or field to set the type for forwarding. Check out:

https://www.elastic.co/guide/en/logstas ... -grok.html
https://assets.nagios.com/downloads/nag ... ilters.pdf
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
Locked