# ELK Searches from Splunk

**URL:** <https://discuss.elastic.co/t/elk-searches-from-splunk/326887>\
**Category:** Elasticsearch\
**Created:** [March 2, 2023, 8:33pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887 "2023-03-02T20:33:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![juancamiloll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juancamiloll/32/110326_2.png) [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Post date:** [March 2, 2023, 8:33pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887/1 "2023-03-02T20:33:36Z")

</div>

Hello

On a single server I have ELK(v 7.6.0) and Splunk.

All sources that support syslog protocol are being ingested to ELK

Taking advantage of some Splunk functionalities a query is made to ELK with this kind of code (| ess eaddr="[http://localhost:9200](http://localhost:9200)" index=paloalto\* tsfield="@timestamp" query="SourceIP:8.8.8.8.8" fields="\*" )

Depending on the amount of matches that the query brings depends on the time in which the information is displayed and I guess it is something for everyone and even obvious.

I have increased the server capabilities to try to improve this performance but as inexperienced I would like to know if you who have more experience than me have knowledge if there is any limitation on the number of events that can be queried from splunk to ELK.

at the moment I have this error message and since it is on the Splunk plugin side I guess I have to investigate how to increase that 60 seconds time that is configured by default.

```auto
External search command 'ess' returned error code 1. Script output = "error_message=ConnectionTimeout at "/var2/splunk/splunk/etc/apps/elasticsplunk/bin/elasticsearch/connection/http_urllib3.py", line 155 : ConnectionTimeout caused by - ReadTimeoutError(HTTPConnectionPool(host=u'localhost', port=9200): Read timed out. (read timeout=60)) ".”

```

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 3, 2023, 6:57pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887/2 "2023-03-03T18:57:57Z")

</div>

Sounds like the issue might be on Splunk's side. I know of no specific rate limit setting on the elasticsearch side. It would be a good idea to make sure your query doesn't take too long to execute though. You can turn on [slow logs](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-slowlog.html) on the index. Also, take a look at your cluster from Stack Monitoring to make sure it isn't hitting a bottleneck. Some more details on what is actually happening on the elastic side would be helpful, but these are some general suggestions when a performance question arises.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 5, 2023, 10:38pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887/3 "2023-03-05T22:38:03Z")

</div>

> [@juancamiloll](#):
>
> ELK(v 7.6.0)

Please note that version is well past [EOL](https://www.elastic.co/support/eol) and no longer supported, you should be looking to upgrade as a matter of urgency.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2023, 10:38pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887/4 "2023-03-05T22:38:03Z")

</div>

7.6.0 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887/5 "2023-04-02T22:39:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
