Ensign ElasticSearch Data Integrator app icon

Ensign ElasticSearch Data Integrator

Splunk modular input for ingesting data from Elasticsearch 8.x clusters by leveraging call the ElasticSearch v8.x REST API. Features multi-cluster profiles, DSL query filters, scroll-based pagination with crash recovery, document-level deduplication, SSL/TLS support, and a full GUI configuration experience. Compatible with Elasticsearch 8.x only and DSL based only,

splunk product badge

Latest Version 1.2.3
May 11, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
Rating

5

(1)

Log in to rate this app
Support
Ensign ElasticSearch Data Integrator support icon
Developer Supported addon
Ensign ElasticSearch Data Integrator is a Splunk modular input add-on for ingesting data from Elasticsearch 8.x clusters into Splunk via the Elasticsearch 8 REST API. Built on the Splunk UCC Framework, it provides a full GUI-driven configuration experience through Splunk Web — no manual file editing required. Key Features: • Multi-cluster Elasticsearch profile management via Splunk UI • DSL Query-focused data retrieval with configurable time-based fetching • ES Scroll API pagination for efficient large-volume data collection • Crash-resilient scroll recovery with a dedicated checkpoint directory • Document-level deduplication guard (rolling 50,000 IDs per stanza) • SSL/TLS certificate verification support • Custom term filters per data source • Global proxy support with Splunk-native credential encryption • Custom sourcetype override per input stanza IMPORTANT: This add-on is designed exclusively for Elasticsearch 8.x API. It is NOT compatible with Elasticsearch 7.x or earlier versions. Compatibility: • Elasticsearch: 8.x only • Splunk Enterprise: 8.2+ and 9.x (You can try for 10.x, let me know the updates) • Python: 3.x (bundled with Splunk)

Categories

IT Operations, Security, Fraud & Compliance

Created By

Muhammad Rafdi Aufar Ahmad

Type

addon

Downloads

15

Resources

Log in to report this app listing