Co

18 views
Skip to first unread message

Marisol Hernández

unread,
Aug 3, 2023, 5:38:38 PM8/3/23
to Wazuh mailing list
Connecting Elasticsearch to Splunk

Does anyone know how to connect Elasticsearch + Kibana with Spluk?

I would like my Wazuh agents to send logs to splunk.

Leonardo Quiceno

unread,
Aug 3, 2023, 7:12:54 PM8/3/23
to Wazuh mailing list
Hi Marisol,

To connect Elasticsearch + Kibana with Splunk, you can use the Splunk HTTP Event Collector (HEC) to receive logs from your Wazuh agents. Here are the steps to follow:

1. Set up the Splunk HEC by enabling it in your Splunk instance and configuring the necessary inputs.2. Configure your Wazuh agents to send logs to Elasticsearch.
3. Install and configure a log forwarder, such as Filebeat, on the Elasticsearch nodes to forward logs to Splunk via the HEC.
4. Configure Filebeat to read logs from Elasticsearch and send them to Splunk using the HEC endpoint.
By following these steps, you will be able to forward logs from your Wazuh agents in Elasticsearch to Splunk for further analysis and monitoring.

I hope it will be useful for you.

Reply all
Reply to author
Forward
0 new messages