<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best Practices for Streaming Logs from Splunk Cloud to External Platforms in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704561#M3364</link>
    <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I need advice on the best approach for streaming logs from &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Platform&lt;/STRONG&gt; to an external platform. The logs are already being ingested into Splunk Cloud from various applications used by my client's organization. Now, the requirement is to forward or stream these logs to an external system for additional processing and analytics.&lt;/P&gt;&lt;P&gt;#Splunk cloud&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nav&lt;/P&gt;</description>
    <pubDate>Sat, 16 Nov 2024 22:12:26 GMT</pubDate>
    <dc:creator>NavS</dc:creator>
    <dc:date>2024-11-16T22:12:26Z</dc:date>
    <item>
      <title>Best Practices for Streaming Logs from Splunk Cloud to External Platforms</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704561#M3364</link>
      <description>&lt;P&gt;Hi Splunk Community,&lt;/P&gt;&lt;P&gt;I need advice on the best approach for streaming logs from &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Platform&lt;/STRONG&gt; to an external platform. The logs are already being ingested into Splunk Cloud from various applications used by my client's organization. Now, the requirement is to forward or stream these logs to an external system for additional processing and analytics.&lt;/P&gt;&lt;P&gt;#Splunk cloud&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nav&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 22:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704561#M3364</guid>
      <dc:creator>NavS</dc:creator>
      <dc:date>2024-11-16T22:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Streaming Logs from Splunk Cloud to External Platforms</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704563#M3365</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274107"&gt;@NavS&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Refer to&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice&lt;/A&gt;&amp;nbsp;for supported data egress methods:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Data Egress&lt;/TD&gt;&lt;TD&gt;Dynamic Data Self-Storage export of aged data per index from Splunk Cloud Platform to Amazon S3 or Google Cloud Storage&lt;/TD&gt;&lt;TD&gt;No limit to the amount of data that can be exported from your indexes to your Amazon S3 or Google Cloud Storage account in the same region.&lt;/TD&gt;&lt;TD&gt;Dynamic Data Self-Storage is designed to export 1 TB of data per hour.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Data Egress&lt;/TD&gt;&lt;TD&gt;Search results via UI or REST API&lt;/TD&gt;&lt;TD&gt;Recommend no more than 10% of ingested data&lt;/TD&gt;&lt;TD&gt;For optimal performance, no single query, or all queries in aggregate over the day from the UI or REST API, should return full results of more than 10% of ingested daily volume. To route data to multiple locations, consider solutions like Ingest Actions, Ingest Processor, or the Edge Processor solution.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Data Egress&lt;/TD&gt;&lt;TD&gt;Search results to Splunk User Behavior Analytics (UBA)&lt;/TD&gt;&lt;TD&gt;No limit&lt;/TD&gt;&lt;TD&gt;Data as a result of search queries to feed into Splunk User Behavior Analytics (UBA).&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;To stream events to both Splunk Cloud and another destination, an intermediate forwarding solution is required.&lt;/P&gt;&lt;P&gt;You should contact your client's Splunk account team for confirmation, but your Splunk Cloud native options are likely limited to the table above.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 23:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704563#M3365</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-11-16T23:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Streaming Logs from Splunk Cloud to External Platforms</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704565#M3366</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49493"&gt;@tscroggins&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 23:08:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Best-Practices-for-Streaming-Logs-from-Splunk-Cloud-to-External/m-p/704565#M3366</guid>
      <dc:creator>NavS</dc:creator>
      <dc:date>2024-11-16T23:08:58Z</dc:date>
    </item>
  </channel>
</rss>

