# Searching a plugin for ELKstack like Splunk app for Stream

**URL:** <https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397>\
**Category:** Logstash\
**Created:** [November 12, 2015, 10:14am UTC](https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397 "2015-11-12T10:14:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![oraant](https://avatars.discourse-cdn.com/v4/letter/o/ce7236/32.png) [@oraant](https://discuss.elastic.co/u/oraant)\
**Post date:** [November 12, 2015, 10:14am UTC](https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397/1 "2015-11-12T10:14:49Z")

</div>

With Splunk app for Stream,when I login into mysql server from host1,the soft will capture the action and generate some message like this:

```
{"endtime":"2015-11-11T08:34:41.080784Z",
"timestamp":"2015-11-11T08:34:41.080784Z",
"count":1,
"src_ip":"192.168.18.132",
"src_port":46773,
"dest_ip":"192.168.18.131",
"dest_port":3306,
"login":"root",
"query":"",
"time_taken":26005,
"psrsvd_ss_time_taken":676260025}

```

And when i run a sql,it will capture the action and generate some message like this:

```
{"endtime":"2015-11-11T01:27:44.104973Z",
"timestamp":"2015-11-11T01:27:44.104973Z",
"count":1,
"src_ip":"192.168.18.132",
"src_port":37159,
"dest_ip":"192.168.18.131",
"dest_port":3306,
"login":"",
"query":"SELECT count(*) FROM `ecshop`.`ecs_category` WHERE is_show = 1 ",
"time_taken":629,
"psrsvd_ss_time_taken":395641}

```

And when I access Apache server,It can got the same thing like the `source IP` and `port`,the `reply time`,the `url I'm looking`,and so on.And it works for Oracle database,Email server,and so on.Here is the link with [Supported procotol](http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/Whattypeofdatadoesthisappcollect).

So,I'm searching plugins for logstash,or ELKstack,which can do things like that,or some software that can collect the information and input into logstash,or some workaround.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 12, 2015, 9:11pm UTC](https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397/2 "2015-11-12T21:11:57Z")

</div>

Have you looked at [PacketBeat](https://www.elastic.co/products/beats/packetbeat)?

---

<div class="post-metadata">

**Author:** ![oraant](https://avatars.discourse-cdn.com/v4/letter/o/ce7236/32.png) [@oraant](https://discuss.elastic.co/u/oraant)\
**Post date:** [November 13, 2015, 4:06am UTC](https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397/3 "2015-11-13T04:06:41Z")

</div>

Thanks bro,but seems like it doesn't support oracle.Is there any way else or some way to extend the PacketBeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:22am UTC](https://discuss.elastic.co/t/searching-a-plugin-for-elkstack-like-splunk-app-for-stream/34397/4 "2017-07-06T05:22:56Z")

</div>


