elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
41 stars 452 forks source link

Change experimental Splunk ingest option to deprecated. #11502

Closed norrietaylor closed 4 weeks ago

norrietaylor commented 1 month ago

Goal Statement This experimental feature of ingesting data from the Splunk HTTP API should be marked as deprecated. We will need to change the text to "deprecated" for each of the affected integrations integrations.

Image

Impact This would impact five integrations (zeek, nginx, windows, apache, and system). There are better ways to accomplish this user outcome with our product. Either by usage of a Splunk package that has the CEL input using reroute_rules.yml or the Cribl integration.

elasticmachine commented 1 month ago

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

elasticmachine commented 1 month ago

Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)