# Splunk Elasticsearch integration

**URL:** <https://discuss.elastic.co/t/splunk-elasticsearch-integration/21384>\
**Category:** Elasticsearch\
**Created:** [December 24, 2014, 3:09pm UTC](https://discuss.elastic.co/t/splunk-elasticsearch-integration/21384 "2014-12-24T15:09:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [December 24, 2014, 3:09pm UTC](https://discuss.elastic.co/t/splunk-elasticsearch-integration/21384/1 "2014-12-24T15:09:11Z")

</div>

Folks,

I wanted to let you know, I have been working on a "search command" for  
splunk that allows me to use the SPLUNK GUI but query data in  
elasticsearch.

I just wanted to let you know it was out there as I never found anything  
similar.  
[https://github.com/eperry/splunk-elasticsearch](https://github.com/eperry/splunk-elasticsearch)

Use Case:

Splunk is very expense to license  
Most data in logfiles are not needed for Management Dashboard needs  
Developers and Middleware like a central location to watch log files, query  
data  
Security and S/A also like to build adhoc reports to discover problems in  
the enviroment.

Problem

To log +100GB a day to meet the Use case splunk is cost prohibitive  
To do everything in ELK, does not meet the complex nature of the data and  
adhoc reports.  
Kibana does not have alot of features that the Splunk Interface has.

Solution:

Create a Splunk search command " | esearch "Query somthing" index=logstash  
.... " that allows commands issued in splunk to query elasticsearch, and  
retrieve the data. This way we can keep one unified interface for both  
Management and developers while avoiding the cost of splunk. Later on as  
people see the power of ELK we maybe able to transition over completely  
but till then.

I welcome anyone to contribute code or look at this, I am a noob in python  
coding and it could use some more cleanup.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0c3dd529-495f-4a1f-a58d-c444ab8f0950%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0c3dd529-495f-4a1f-a58d-c444ab8f0950%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:42am UTC](https://discuss.elastic.co/t/splunk-elasticsearch-integration/21384/2 "2017-07-06T00:42:02Z")

</div>


