Skip to main content
Elastic Search Add-on for Splunk app icon

Elastic Search Add-on for Splunk

The Elastic Search Add-on for Splunk collects indexed data from an Elasticsearch instance and ingests it into Splunk as JSON events.Built by Vatsal Jagani
splunk product badge

Default Version 1.0.0

April 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2

Rating
0
(0)

Log in to rate this app

Support
Not Supported

The Elastic Search Add-on for Splunk collects indexed data from an Elasticsearch instance and ingests it into Splunk as JSON events. It uses the official Elasticsearch Python SDK and manages per-input checkpoints to ensure only new data is fetched on each run.