<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Seeking Solutions for Forwarding Splunk Metadata to Third-Party Systems Over TCP/HTTP in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745932#M22230</link>
    <description>&lt;P&gt;See my response in your other thread.&lt;/P&gt;</description>
    <pubDate>Mon, 12 May 2025 06:24:03 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-05-12T06:24:03Z</dc:date>
    <item>
      <title>Seeking Solutions for Forwarding Splunk Metadata to Third-Party Systems Over TCP/HTTP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745926#M22227</link>
      <description>&lt;P&gt;I want to forward logs to a third-party system over HTTP, but I found in the Splunk documentation that forwarding logs to third-party systems is typically done over TCP. I tried using TCP, but I did not receive Splunk metadata like&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;host,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;sourcetype,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;source, and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;index&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the third-party system.&lt;/P&gt;&lt;P&gt;Is it possible to forward logs with metadata to a third-party system over HTTP? If not, how can I get Splunk metadata over TCP? Can anyone suggest a solution?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149"&gt;@splunk&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193662"&gt;@splunkent2&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276838"&gt;@Splunk9&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276851"&gt;@msplunk&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/72423"&gt;@splunk0&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 05:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745926#M22227</guid>
      <dc:creator>sudha_krish</dc:creator>
      <dc:date>2025-05-12T05:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Solutions for Forwarding Splunk Metadata to Third-Party Systems Over TCP/HTTP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745930#M22228</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308717"&gt;@sudha_krish&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk forwarders (Universal or Heavy) send only &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;raw event data&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; to non-Splunk systems over TCP or syslog by default, as outlined in the Splunk documentation. Metadata such as &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;host&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sourcetype&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;, and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;index&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; is internal to Splunk and not included in the raw event payload.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;To forward logs with metadata over HTTP reliably, tools like &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Cribl Stream&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;are commonly used. These tools can intercept Splunk data, enrich it with metadata, and send it to third-party systems via HTTP.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Cribl (&lt;/SPAN&gt;&lt;A href="https://cribl.io/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://cribl.io/&lt;/A&gt;&lt;SPAN&gt;) allows you to route events to multiple systems but maintain full metadata. In addition, you can be very selective about what goes where and you can reshape and enrich events as they're moving.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 12 May 2025 06:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745930#M22228</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-12T06:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Solutions for Forwarding Splunk Metadata to Third-Party Systems Over TCP/HTTP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745931#M22229</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308717"&gt;@sudha_krish&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sending out over HTTP does not use an open HTTP standard/API - it uses Splunk2Splunk protocol wrapped in HTTP, so therefore it is only supported for sending to other Splunk systems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to send data to a non-Splunk system you can look at the syslog forwarding, however this sends the raw events before they are parsed.&lt;/P&gt;&lt;P&gt;For more information on sending to external systems please check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Forwarddatatothird-partysystemsd" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 06:22:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745931#M22229</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-12T06:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Solutions for Forwarding Splunk Metadata to Third-Party Systems Over TCP/HTTP</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745932#M22230</link>
      <description>&lt;P&gt;See my response in your other thread.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 06:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Seeking-Solutions-for-Forwarding-Splunk-Metadata-to-Third-Party/m-p/745932#M22230</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-05-12T06:24:03Z</dc:date>
    </item>
  </channel>
</rss>

