Default Version 1.0.0
April 24, 2026
April 24, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2
Log in to rate this app
The Elastic Search Add-on for Splunk collects indexed data from an Elasticsearch instance and ingests it into Splunk as JSON events. It uses the official Elasticsearch Python SDK and manages per-input checkpoints to ensure only new data is fetched on each run.
Log in to report this app listing.