Page 1 of 1

Elasticsearch Data Integrator - Modular Input

Posted: Mon Feb 08, 2021 3:01 pm
by funderburg78
https://splunkbase.splunk.com/app/4175/

Has anyone attempted to use the above connector to get data from Nagios to Splunk? I have a Also, anyone know if there is an easy way to parse data so that devices with seperate data formats can be input as different sourcetypes into splunk?

Re: Elasticsearch Data Integrator - Modular Input

Posted: Tue Feb 09, 2021 3:27 pm
by cdienger
Welcome to the forums, @funderburg78!

I'm not aware of anyone using the component you've linked to, but it is possible to create an output in NLS that will send logs to a remote Splunk server:

https://support.nagios.com/forum/viewto ... 38&t=47443

A grok filter can be set up to parse the log lines and set a tag or field to set the type for forwarding. Check out:

https://www.elastic.co/guide/en/logstas ... -grok.html
https://assets.nagios.com/downloads/nag ... ilters.pdf