Polarity Elasticsearch Integration
Polarity's Elasticsearch integration allows a user to connect to an Elasticsearch instance. The integration returns the number of records for an IP that are present for a given entity. A user can also link out to their Kibana instance to view more information.
Elasticsearch Integration Options
This setting is the hostname of your Elasicsearch instance. Please do not include the Scheme or Port if there is one. For example:
The default for port for Elasticsearch is 9200. If you have changed your port when setting up your instance, please change the port here.
Username set for an individual user or if you have a generic RestAPI user, you can set it here. It is only required if you have established credentials on your Elasticsearch instance
Password set for the individual user or generic user. It is only required if you have established credentials on your Elasticsearch instance
Provide the Index with Elasticsearch that you want to search against.
Provide the type of index that you are performing your searches against.
This the exact hostname that you go to in order to access the Splunk User-Interface. If there is a port or a protocal used, please ensure they are included. For example:
Installation instructions for integrations are provided on the PolarityIO GitHub Page.
Polarity is a memory-augmentation platform that improves and accelerates analyst decision making. For more information about the Polarity platform please see: