A Search command to explore Elasticsearch data within Splunk.
When searching with the ess command, it uses by default the Splunk timepicker provided time range unless the earliest and latest parameters are specified. When earliest and latest parameters are specified this will be the effective range for the search, even though the range below the search bar shows the one from the timepicker.
|ess eaddr="https://node1:9200,https://node2:9200" index=indexname tsfield="@timestamp" query="field:value AND host:host*"
|ess eaddr="https://node1:9200,https://node2:9200" index=indexname tsfield="@timestamp" latest=now earliest="now-24h" query="field:value AND host:host*"
|ess eaddr="https://node1:9200,https://node2:9200" action=indices-list"
|ess eaddr="https://node1:9200,https://node2:9200" action=cluster-health"
Written by Bruno Moura brunotm@gmail.com